Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37303
HistorySep 27, 2022 - 1:08 p.m.

Authentication Bypass

2022-09-2713:08:32
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14
consul
authentication
bypass
vulnerability
uri
length checks
csr requests
attacker
multiple san uri

0.001 Low

EPSS

Percentile

49.8%

github.com/hashicorp/consul is vulnerable to authentication bypass. The vulnerability exists in auto_config_endpoint.go and leader_connect_ca.go because the URI length checks are not added to CSR requests which allows an attacker to designate multiple SAN URI values in a call to the endpoint.

References