HashiCorp Consul and Consul Enterprise 1.16.0 when using JWT Auth for service mesh incorrectly allows/denies access regardless of service identities. Fixed in 1.16.1.
{
"cna_assigner": "HashiCorp",
"cwe_ids": [
"CWE-266"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/3xxx/CVE-2023-3518.json"
}{
"cpe": [
"cpe:2.3:a:hashicorp:consul:1.16.0:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:hashicorp:consul:1.16.0:-:*:*:-:*:*:*",
"cpe:2.3:a:hashicorp:consul:1.16.0:rc1:*:*:-:*:*:*"
],
"source": [
"AFFECTED_FIELD",
"CPE_STRING"
],
"extracted_events": [
{
"introduced": "1.16.0"
},
{
"last_affected": "1.16.0"
},
{
"introduced": "1.16.0-NA"
},
{
"last_affected": "1.16.0-NA"
},
{
"introduced": "1.16.0-rc1"
},
{
"last_affected": "1.16.0-rc1"
}
]
}