HashiCorp Consul and Consul Enterprise 1.16.0 when using JWT Auth for service mesh incorrectly allows/denies access regardless of service identities. Fixed in 1.16.1.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Consul | Hashicorp | 1.16.0 (including) | 1.16.0 (including) |
Consul | Hashicorp | 1.16.0-rc1 (including) | 1.16.0-rc1 (including) |