CVE-2024-10086
30.10.2024, 22:15
A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and lead to reflected XSS.
Vendor | Product | Version |
---|---|---|
hashicorp | consul | 1.4.1 ≤ 𝑥 < 1.15.15 |
hashicorp | consul | 1.4.1 ≤ 𝑥 < 1.20.0 |
hashicorp | consul | 1.18.0 ≤ 𝑥 < 1.18.5 |
hashicorp | consul | 1.19.0 ≤ 𝑥 < 1.19.3 |
𝑥
= Vulnerable software versions