CVE-2024-10005
EUVD-2024-302030.10.2024, 22:15
A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using URL paths in L7 traffic intentions could bypass HTTP request path-based access rules.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hashicorp | consul | 1.4.1 ≤ 𝑥 < 1.20.1 |
| hashicorp | consul | 1.9.0 ≤ 𝑥 < 1.15.15 |
| hashicorp | consul | 1.18.0 ≤ 𝑥 < 1.18.5 |
| hashicorp | consul | 1.19.0 ≤ 𝑥 < 1.19.3 |
| hashicorp | consul | 1.20.0 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| hashicorp | consul | 1.9.0 ≤ 𝑥 < 1.20.1 | ADP |
| hashicorp | consul | 1.9.0 ≤ 𝑥 < 1.20.1 | ADP |