A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using URL paths in L7 traffic intentions could bypass HTTP request path-based access rules.
{
"severity": "Medium",
"cpes": [
"cpe:2.3:a:hashicorp:consul:*:*:*:*:*:*:*:*",
"cpe:2.3:a:hashicorp:consul:*:*:*:*:*:go:*:*",
"cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:go:*:*"
]
}