HashiCorp Consul and Consul Enterprise 1.9.0 through 1.10.0 default deny policy with a single L7 application-aware intention deny action cancels out, causing the intention to incorrectly fail open, allowing L4 traffic. Fixed in 1.9.8 and 1.10.1.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-1451 HashiCorp Consul and Consul Enterprise 1.9.0 through 1.10.0 default deny policy with a single L7 application-aware intention deny action cancels out, causing the intention to incorrectly fail open, allowing L4 traffic. Fixed in 1.9.8 and 1.10.1.
Github GHSA Github GHSA GHSA-8h2g-r292-j8xh HashiCorp Consul L7 deny intention results in an allow action
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T00:54:50.693Z

Reserved: 2021-07-07T00:00:00

Link: CVE-2021-36213

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-07-17T18:15:07.820

Modified: 2024-11-21T06:13:19.590

Link: CVE-2021-36213

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses