CVE Vulnerabilities

CVE-2021-32574

Improper Certificate Validation

Published: Jul 17, 2021 | Modified: Oct 25, 2022
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

HashiCorp Consul and Consul Enterprise 1.3.0 through 1.10.0 Envoy proxy TLS configuration does not validate destination service identity in the encoded subject alternative name. Fixed in 1.8.14, 1.9.8, and 1.10.1.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Consul Hashicorp 1.3.0 (including) 1.8.14 (excluding)
Consul Hashicorp 1.9.0 (including) 1.9.8 (excluding)
Consul Hashicorp 1.10.0 (including) 1.10.1 (excluding)

Potential Mitigations

References