CVE Vulnerabilities

CVE-2021-32574

Improper Certificate Validation

Published: Jul 17, 2021 | Modified: Oct 25, 2022
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

HashiCorp Consul and Consul Enterprise 1.3.0 through 1.10.0 Envoy proxy TLS configuration does not validate destination service identity in the encoded subject alternative name. Fixed in 1.8.14, 1.9.8, and 1.10.1.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Consul Hashicorp 1.3.0 (including) 1.8.14 (excluding)
Consul Hashicorp 1.9.0 (including) 1.9.8 (excluding)
Consul Hashicorp 1.10.0 (including) 1.10.1 (excluding)
Consul Ubuntu bionic *
Consul Ubuntu groovy *
Consul Ubuntu hirsute *
Consul Ubuntu impish *
Consul Ubuntu kinetic *
Consul Ubuntu trusty *
Consul Ubuntu xenial *

Potential Mitigations

References