CVE Vulnerabilities

CVE-2022-40716

Unchecked Return Value

Published: Sep 23, 2022 | Modified: Nov 07, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Ubuntu
MEDIUM

HashiCorp Consul and Consul Enterprise up to 1.11.8, 1.12.4, and 1.13.1 do not check for multiple SAN URI values in a CSR on the internal RPC endpoint, enabling leverage of privileged access to bypass service mesh intentions. Fixed in 1.11.9, 1.12.5, and 1.13.2.

Weakness

The product does not check the return value from a method or function, which can prevent it from detecting unexpected states and conditions.

Affected Software

Name Vendor Start Version End Version
Consul Hashicorp * 1.11.9 (excluding)
Consul Hashicorp 1.12.0 (including) 1.12.5 (excluding)
Consul Hashicorp 1.13.0 (including) 1.13.2 (excluding)
Consul Ubuntu bionic *
Consul Ubuntu kinetic *
Consul Ubuntu mantic *

Potential Mitigations

References