Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has permission to modify the service(s) corresponding to those modified proxies.
2023-06-02T23:15:09.503
2024-11-21T07:59:20.730
Modified
CVSSv3.1: 8.7 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | hashicorp | consul | < 1.15.3 | Yes |
Application | hashicorp | consul | < 1.15.3 | Yes |