DirectorySecurity Advisories
Sign In
Security Advisories

CGA-2436-cwr3-m3xr

Published

Last updated

https://images.chainguard.dev/security/CGA-2436-cwr3-m3xr
Package

consul-1.17-fips

Latest Update
Not affected
Aliases
  • CVE-2021-32574
  • GHSA-25gf-8qrr-g78r

Severity

7.5

High

CVSS V3

Summary

Hashicorp Consul Missing SSL Certificate Validation

Description

HashiCorp Consul before 1.10.1 (and Consul Enterprise) has Missing SSL Certificate Validation. xds does not ensure that the Subject Alternative Name of an upstream is validated.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images