Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers
High severity
GitHub Reviewed
Published
Aug 9, 2023
to the GitHub Advisory Database
•
Updated Sep 26, 2024
Description
Published by the National Vulnerability Database
Aug 9, 2023
Published to the GitHub Advisory Database
Aug 9, 2023
Reviewed
Apr 1, 2024
Last updated
Sep 26, 2024
A vulnerability was identified in Consul such that using JWT authentication for service mesh incorrectly allows/denies access regardless of service identities. This vulnerability, CVE-2023-3518, affects Consul 1.16.0 and was fixed in 1.16.1.
References