CVE-2024-10006

HIGH8.3EPSS 0.03%

Hashicorp Consul Improper Neutralization of HTTP Headers for Scripting Syntax vulnerability

Published: 10/31/2024Modified: 4/28/2026

Description

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.

Affected packages (4)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L
osvCVSS 3.1HIGH8.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

References (9)