Improper authorization control for web services In github.com/hashicorp/consul/acl
Description
Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers A vulnerability was identified in Consul such that using JWT authentication for service mesh incorrectly allows/denies access regardless of service identities. This vulnerability, CVE-2023-3518, affects Consul 1.16.0 and was fixed in 1.16.1.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 1.16.1 | ||
go | 1.16.1 | ||
go | 1.16.1 |
Aliases
1. 2. 3. 4.
References
1. 2.