Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has permission to modify the service(s) corresponding to those modified proxies.
{
"github_reviewed": true,
"nvd_published_at": "2023-06-02T23:15:09Z",
"github_reviewed_at": "2023-06-06T02:04:22Z",
"severity": "HIGH",
"cwe_ids": [
"CWE-266"
]
}