CVE-2024-10006

HIGH8.3EPSS 0.03%

Consul L7 Intentions Vulnerable To Headers Bypass

發布日:2024/10/31修改日:2025/5/20
也稱為:GHSA-5c4w-8hhh-3c3hBIT-consul-2024-10006CGA-pcg4-47ff-wfqvGO-2024-3241

描述

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.

受影響套件(4)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L
osvCVSS 3.1HIGH8.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

參考連結(9)