Lucene search

K
nvd[email protected]NVD:CVE-2022-40716
HistorySep 23, 2022 - 12:15 p.m.

CVE-2022-40716

2022-09-2312:15:10
CWE-252
web.nvd.nist.gov
1
hashicorp
consul
consul enterprise
san uri
csr
rpc endpoint
privileged access
service mesh intentions
security vulnerability
cve-2022-40716

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

49.8%

HashiCorp Consul and Consul Enterprise up to 1.11.8, 1.12.4, and 1.13.1 do not check for multiple SAN URI values in a CSR on the internal RPC endpoint, enabling leverage of privileged access to bypass service mesh intentions. Fixed in 1.11.9, 1.12.5, and 1.13.2."

Affected configurations

NVD
Node
hashicorpconsulRange<1.11.9-
OR
hashicorpconsulRange<1.11.9enterprise
OR
hashicorpconsulRange1.12.01.12.5-
OR
hashicorpconsulRange1.12.01.12.5enterprise
OR
hashicorpconsulRange1.13.01.13.2-
OR
hashicorpconsulRange1.13.01.13.2enterprise

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

49.8%