Hashicorp Consul allows user with service:write permissions to patch remote proxy instances
High severity
GitHub Reviewed
Published
Jun 3, 2023
to the GitHub Advisory Database
•
Updated Sep 26, 2024
Package
Affected versions
>= 1.15.0, < 1.15.3
Patched versions
1.15.3
Description
Published by the National Vulnerability Database
Jun 2, 2023
Published to the GitHub Advisory Database
Jun 3, 2023
Reviewed
Jun 6, 2023
Last updated
Sep 26, 2024
Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has permission to modify the service(s) corresponding to those modified proxies.
References