DirectorySecurity Advisories
Sign In
Security Advisories

CGA-x38p-p6h4-33cc

Published

Last updated

https://images.chainguard.dev/security/CGA-x38p-p6h4-33cc
Package

traefik

Latest Update
Fixed
Fixed Version

2.9.8-r1

Aliases
  • CVE-2021-41803
  • GHSA-hr3v-8cp3-68rf

Severity

7.1

High

CVSS V3

Summary

HashiCorp Consul does not properly validate node or segment names prior to usage in JWT claim assertions

Description

HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 did not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC. Fixed in 1.11.9, 1.12.5, and 1.13.2.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images