A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.
{
"cpes": [
"cpe:2.3:a:hashicorp:consul:*:*:*:*:*:*:*:*",
"cpe:2.3:a:hashicorp:consul:*:*:*:*:*:go:*:*",
"cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:go:*:*"
],
"severity": "Medium"
}