HashiCorp Consul vulnerable to Origin Validation Error
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jun 9, 2023
Description
Published by the National Vulnerability Database
Mar 26, 2019
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jun 9, 2023
Last updated
Jun 9, 2023
HashiCorp Consul 1.4.3 lacks server hostname verification for agent-to-agent TLS communication. In other words, the product behaves as if
verify_server_hostname
were set to false, even when it is actually set to true. This is fixed in 1.4.4.References