| |
Vulnerability CVE-2023-2816
Published: 2023-06-02 Modified: 2023-06-03
Description: |
Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has permission to modify the service(s) corresponding to those modified proxies. |
References: |
https://discuss.hashicorp.com/t/hcsec-2023-16-consul-envoy-extension-downstream-proxy-configuration-by-upstream-service-owner/54525
|
|
|
Copyright 2024, cxsecurity.com
|
|
|