A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and lead to reflected XSS.
2024-10-30T22:15:03.283
2025-01-10T13:15:08.623
Modified
CVSSv3.1: 6.1 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | hashicorp | consul | < 1.15.15 | Yes |
Application | hashicorp | consul | < 1.20.0 | Yes |
Application | hashicorp | consul | < 1.18.5 | Yes |
Application | hashicorp | consul | < 1.19.3 | Yes |