PT-2021-21178 · Hashicorp · Hashicorp Consul Enterprise+1
Published
2021-07-17
·
Updated
2024-08-21
·
CVE-2021-36213
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
HashiCorp Consul and Consul Enterprise versions 1.9.0 through 1.10.0
Description
The issue arises when a default deny policy with a single L7 application-aware intention deny action is used, causing the intention to incorrectly fail open and allow L4 traffic. This occurs due to a situation generated by xds where a single L7 deny intention results in an allow action when a default deny policy is in place.
Recommendations
For HashiCorp Consul and Consul Enterprise versions 1.9.0 through 1.9.7, update to version 1.9.8 to resolve the issue.
For HashiCorp Consul and Consul Enterprise version 1.10.0, update to version 1.10.1 to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hashicorp Consul Enterprise
Hashicorp Consul