QID 375765

Date Published: 2021-08-04

QID 375765: HashiCorp Consul/Consul Enterprise Intentions Deny Action And TLS Configuration Vulnerability

Consul is a service mesh solution providing a full featured control plane with service discovery, configuration, and segmentation functionality. Each of these features can be used individually as needed, or they can be used together to build a full service mesh.

Affected versions:
Consul and Consul Enterprise 1.9.0 through 1.10.0;
Consul and Consul Enterprise 1.3.0 through 1.10.0;
QID Detection Logic:
This QID detects vulnerable versions of Consul.

Impacted is confidentiality, integrity, and availability.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The Vendor has released security update to fix the vulnerability. For more information please visit HCSEC-2021-16HCSEC-2021-17

    CVEs related to QID 375765

    Software Advisories
    Advisory ID Software Component Link
    HCSEC-2021-16 URL Logo discuss.hashicorp.com/t/hcsec-2021-16-consul-s-application-aware-intentions-deny-action-fails-open-when-combined-with-default-deny-policy/26855
    HCSEC-2021-17 URL Logo discuss.hashicorp.com/t/hcsec-2021-17-consul-s-envoy-tls-configuration-did-not-validate-destination-service-subject-alternative-names/26856