PT-2021-21178 · Hashicorp · Hashicorp Consul Enterprise+1

Published

2021-07-17

·

Updated

2024-08-21

·

CVE-2021-36213

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions HashiCorp Consul and Consul Enterprise versions 1.9.0 through 1.10.0
Description The issue arises when a default deny policy with a single L7 application-aware intention deny action is used, causing the intention to incorrectly fail open and allow L4 traffic. This occurs due to a situation generated by xds where a single L7 deny intention results in an allow action when a default deny policy is in place.
Recommendations For HashiCorp Consul and Consul Enterprise versions 1.9.0 through 1.9.7, update to version 1.9.8 to resolve the issue. For HashiCorp Consul and Consul Enterprise version 1.10.0, update to version 1.10.1 to resolve the issue.

Fix

Related Identifiers

BIT-CONSUL-2021-36213
CVE-2021-36213
GHSA-8H2G-R292-J8XH
GO-2022-0895

Affected Products

Hashicorp Consul Enterprise
Hashicorp Consul