7.3

CVE-2023-3518

JWT Auth in L7 Intentions Allow For Mismatched Service Identity and JWT Providers for Access

HashiCorp Consul and Consul Enterprise 1.16.0 when using JWT Auth for service mesh incorrectly allows/denies access regardless of service identities. Fixed in 1.16.1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hashicorp ≫ Consul Version 1.16.0 SwEdition enterprise
Hashicorp ≫ Consul Version 1.16.0 Update - SwEdition -
Hashicorp ≫ Consul Version 1.16.0 Update rc1 SwEdition -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.45% 0.368
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.3 3.9 3.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
security@hashicorp.com 7.4 3.1 3.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
CWE-266 Incorrect Privilege Assignment

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

https://discuss.hashicorp.com/t/hcsec-2023-25-consul-jwt-auth-in-l7-intentions-allow-for-mismatched-service-identity-and-jwt-providers/57004
Vendor Advisory