CVE-2021-36213

HIGH7.5EPSS 0.77%

HashiCorp Consul L7 deny intention results in an allow action

Published: 7/19/2021Modified: 2/4/2026

Description

In HashiCorp Consul before 1.10.1 (and Consul Enterprise), xds can generate a situation where a single L7 deny intention (with a default deny policy) results in an allow action.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

References (7)