HashiCorp Consul 1.4.3 lacks server hostname verification for agent-to-agent TLS communication. In other words, the product behaves as if verify_server_hostname were set to false, even when it is actually set to true. This is fixed in 1.4.4.
The product does not properly verify that the source of data or communication is valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Consul | Hashicorp | 1.4.3 (including) | 1.4.3 (including) |
Consul | Ubuntu | bionic | * |
Consul | Ubuntu | trusty | * |