CVE-2024-10006

HIGH8.3EPSS 0.03%

Consul L7 Intentions Vulnerable To Headers Bypass

Published: 10/31/2024Modified: 5/20/2025
Also known as:GHSA-5c4w-8hhh-3c3hBIT-consul-2024-10006CGA-pcg4-47ff-wfqvGO-2024-3241

Description

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.

Affected packages (4)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L
osvCVSS 3.1HIGH8.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

References (9)