HashiCorp Consul does not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2024-2683" }
{ "imports": [ { "path": "github.com/hashicorp/consul/agent/consul", "symbols": [ "AutoConfig.InitialConfiguration", "jwtAuthorizer.Authorize" ] } ] }