Fiche vulnérabilité
CVE-2021-32574 : faille élevée hashicorp consul (CVSS 7.5)
Description
HashiCorp Consul and Consul Enterprise 1.3.0 through 1.10.0 Envoy proxy TLS configuration does not validate destination service identity in the encoded subject alternative name. Fixed in 1.8.14, 1.9.8, and 1.10.1.
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 17 juil. 2021
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- hashicorp consul