CVE-2021-41803
Improper handling of node names in JWT claims assertions in github.com/hashicorp/consul
7.1
HIGH
CVSS 3.1
EPSS 0.85%
Description
HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC. Fixed in 1.11.9, 1.12.5, and 1.13.2."
How to fix CVE-2021-41803
To remediate CVE-2021-41803, upgrade the affected package to a fixed version below.
- —upgrade to 1.11.9 or later
- —no fix listed
- —upgrade to 1.11.9 or later
- —upgrade to 1.11.9 or later
Is CVE-2021-41803 being exploited?
Low — EPSS is 0.8%, meaning exploitation activity has not been observed at scale.
Affected packages (4)
- >= 1.8.1, < 1.11.9, >= 1.12.4, < 1.12.5, >= 1.13.1, < 1.13.2
- from 0
- >= 1.8.1, < 1.11.9
- >= 1.8.1, < 1.11.9, >= 1.12.0, < 1.12.5, >= 1.13.0, < 1.13.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H |