CVE-2021-32574

Source
https://cve.org/CVERecord?id=CVE-2021-32574
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-32574.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-32574
Aliases
Downstream
CGA (6)
DEBIAN (1)
UBUNTU (1)
Related
Published
2021-07-17T18:15:07Z
Modified
2026-07-09T00:06:10Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

HashiCorp Consul and Consul Enterprise 1.3.0 through 1.10.0 Envoy proxy TLS configuration does not validate destination service identity in the encoded subject alternative name. Fixed in 1.8.14, 1.9.8, and 1.10.1.

References

Affected packages

Git / github.com/hashicorp/consul

Affected ranges

Type
GIT
Repo
https://github.com/hashicorp/consul
Events
Database specific
Show details
{
    "cpe":  [
        "cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:*",
        "cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*"
    ],
    "extracted_events":  [
        {
            "introduced":  "1.3.0"
        },
        {
            "fixed":  "1.8.14"
        },
        {
            "introduced":  "1.9.0"
        },
        {
            "fixed":  "1.9.8"
        },
        {
            "introduced":  "1.10.0"
        },
        {
            "fixed":  "1.10.1"
        }
    ],
    "source":  [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-32574.json"