CVE-2021-36213
17.07.2021, 18:15
HashiCorp Consul and Consul Enterprise 1.9.0 through 1.10.0 default deny policy with a single L7 application-aware intention deny action cancels out, causing the intention to incorrectly fail open, allowing L4 traffic. Fixed in 1.9.8 and 1.10.1.Enginsight
Vendor | Product | Version |
---|---|---|
hashicorp | consul | 1.9.0 ≤ 𝑥 < 1.9.8 |
hashicorp | consul | 1.9.0 ≤ 𝑥 < 1.9.8 |
hashicorp | consul | 1.10.0 ≤ 𝑥 < 1.10.1 |
hashicorp | consul | 1.10.0 ≤ 𝑥 < 1.10.1 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References