CVE Vulnerabilities

CVE-2021-28156

Published: Apr 20, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

HashiCorp Consul Enterprise version 1.8.0 up to 1.9.4 audit log can be bypassed by specifically crafted HTTP events. Fixed in 1.9.5, and 1.8.10.

Affected Software

NameVendorStart VersionEnd Version
ConsulHashicorp1.8.0 (including)1.8.10 (excluding)
ConsulHashicorp1.9.0 (including)1.9.5 (excluding)
ConsulUbuntubionic*
ConsulUbuntufocal*
ConsulUbuntugroovy*
ConsulUbuntuhirsute*
ConsulUbuntuimpish*
ConsulUbuntukinetic*
ConsulUbuntutrusty*

References