DirectorySecurity Advisories
Sign In
Security Advisories

CGA-mrrg-76rp-w9gq

Published

Last updated

https://images.chainguard.dev/security/CGA-mrrg-76rp-w9gq
Package

consul-1.16

Latest Update
Not affected
Aliases
  • CVE-2021-32574
  • GHSA-25gf-8qrr-g78r

Severity

7.5

High

CVSS V3

Summary

Hashicorp Consul Missing SSL Certificate Validation

Description

HashiCorp Consul before 1.10.1 (and Consul Enterprise) has Missing SSL Certificate Validation. xds does not ensure that the Subject Alternative Name of an upstream is validated.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images