ZeroHour

CVE-2023-2816

CVSS 3.1
6.5 medium
EPSS
<1%p46
Published
()
Modified
Description

Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has permission to modify the service(s) corresponding to those modified proxies.

Vendors
hashicorp
Products
consul
Weakness
CWE-266
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.