CVE-2023-3518

Source
https://cve.org/CVERecord?id=CVE-2023-3518
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-3518.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-3518
Aliases
Related
Published
2023-08-09T15:06:52.406Z
Modified
2026-07-15T01:48:49.837604908Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L CVSS Calculator
Summary
JWT Auth in L7 Intentions Allow For Mismatched Service Identity and JWT Providers for Access
Details

HashiCorp Consul and Consul Enterprise 1.16.0 when using JWT Auth for service mesh incorrectly allows/denies access regardless of service identities. Fixed in 1.16.1.

Database specific
{
    "cna_assigner": "HashiCorp",
    "cwe_ids": [
        "CWE-266"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/3xxx/CVE-2023-3518.json"
}
References

Affected packages

Git / github.com/hashicorp/consul

Affected ranges

Type
GIT
Repo
https://github.com/hashicorp/consul
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:hashicorp:consul:1.16.0:*:*:*:enterprise:*:*:*",
        "cpe:2.3:a:hashicorp:consul:1.16.0:-:*:*:-:*:*:*",
        "cpe:2.3:a:hashicorp:consul:1.16.0:rc1:*:*:-:*:*:*"
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_STRING"
    ],
    "extracted_events": [
        {
            "introduced": "1.16.0"
        },
        {
            "last_affected": "1.16.0"
        },
        {
            "introduced": "1.16.0-NA"
        },
        {
            "last_affected": "1.16.0-NA"
        },
        {
            "introduced": "1.16.0-rc1"
        },
        {
            "last_affected": "1.16.0-rc1"
        }
    ]
}

Affected versions

1.*
1.16.0
1.16.0-rc1
v1.*
v1.16.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-3518.json"