7.1
CVSSv3

CVE-2021-41803

Published: 23/09/2022 Updated: 07/11/2023
CVSS v3 Base Score: 7.1 | Impact Score: 4.2 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC. Fixed in 1.11.9, 1.12.5, and 1.13.2."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hashicorp consul 1.12.4

hashicorp consul 1.13.1

hashicorp consul

Vendor Advisories

Debian Bug report logs - #1034841 consul: CVE-2021-41803 Package: src:consul; Maintainer for src:consul is Debian Go Packaging Team <pkg-go-maintainers@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Tue, 25 Apr 2023 18:57:04 UTC Severity: grave Tags: security, upstream Reply or ...

Github Repositories

CG Images vs Docker Images w/Updated OS Packages Why not use popular Docker hub images, update all the OS packages, and call it a day? Target Images (2023-07-12) The analysis is completed on a set of popular Docker images: Popular official docker images Pull Rank Image Docker CG 1 alpine 2 nginx nginx:latest cgrdev/chainguard/nginx:latest 3 busybox busybox:lates