CVE-2021-41803

HIGH7.1EPSS 0.31%

Improper handling of node names in JWT claims assertions in github.com/hashicorp/consul

Published: 9/25/2022Modified: 4/3/2025
Also known as:GHSA-hr3v-8cp3-68rfBIT-consul-2021-41803GO-2024-2683

Description

HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC. Fixed in 1.11.9, 1.12.5, and 1.13.2."

Affected packages (4)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H

References (12)