Consul L7 Intentions Vulnerable To Headers Bypass
A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.
02 / AFFECTED SOFTWARE
Affected packages
46 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.
A vulnerability was identified in Consul and Consul Enterprise ("Consul") such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.
Hashicorp Consul Improper Neutralization of HTTP Headers for Scripting Syntax vulnerability in github.com/hashicorp/consul
A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.
05 / REFERENCES
Further evidence
- https://discuss.hashicorp.com/t/hcsec-2024-23-consul-l7-intentions-vulnerable-to-headers-bypass
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/10xxx/CVE-2024-10006.json
- https://github.com/hashicorp/consul
- https://nvd.nist.gov/vuln/detail/CVE-2024-10006
- https://security.netapp.com/advisory/ntap-20250110-0005/
- https://github.com/hashicorp/consul/commit/d9206fc7e284a9244af4d62f8653a63ca30bd00c
- https://github.com/hashicorp/consul/pull/21816
- https://security.netapp.com/advisory/ntap-20250110-0005
- https://github.com/advisories/GHSA-5c4w-8hhh-3c3h