A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and lead to reflected XSS.
{ "cpes": [ "cpe:2.3:a:hashicorp:consul:*:*:*:*:*:*:*:*", "cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*", "cpe:2.3:a:hashicorp:consul:*:*:*:*:*:go:*:*", "cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:go:*:*" ], "severity": "Medium" }