PT-2021-21583 · Hashicorp+3 · Hashicorp Consul Enterprise+4

Published

2021-09-07

·

Updated

2024-08-21

·

CVE-2021-37219

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HashiCorp Consul and Consul Enterprise versions prior to 1.8.15 HashiCorp Consul and Consul Enterprise versions prior to 1.9.9 HashiCorp Consul and Consul Enterprise versions prior to 1.10.2
Description The issue allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation.
Recommendations For versions prior to 1.8.15, update to version 1.8.15 or later. For versions prior to 1.9.9, update to version 1.9.9 or later. For versions prior to 1.10.2, update to version 1.10.2 or later.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3445
ALT-PU-2023-7106
ALT-PU-2024-8028
BIT-CONSUL-2021-37219
CVE-2021-37219
GHSA-CCW8-7688-VQX4
GO-2022-0593

Affected Products

Alt Linux
Astra Linux
Hashicorp Consul Enterprise
Debian
Hashicorp Consul