Vulnerability CVE-2023-2816


Published: 2023-06-02   Modified: 2023-06-03

Description:
Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has permission to modify the service(s) corresponding to those modified proxies.

 References:
https://discuss.hashicorp.com/t/hcsec-2023-16-consul-envoy-extension-downstream-proxy-configuration-by-upstream-service-owner/54525

Copyright 2024, cxsecurity.com

 

Back to Top