SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-2816

Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has permission to…

MEDIUM 6.5EPSS 0.58%

Does this matter?

Lower severity and a low EPSS score (0.58%). Track it; it rarely justifies an emergency change on its own.

Description

Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has permission to modify the service(s) corresponding to those modified proxies.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
0.58% probability · 46th percentile
CISA KEV
Not listed
Weakness
CWE-266
Affected
hashicorp/consul
Source
security@hashicorp.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.