CVE-2021-37219
HIGHHashiCorp Consul <1.8.15, 1.10.1 - Privilege Escalation via Raft RPC Layer
Title source: llmDescription
HashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.8.15, 1.9.9 and 1.10.2.
References (3)
Core 3
Core References
Product, Vendor Advisory x_refsource_misc
https://www.hashicorp.com/blog/category/consul
Vendor Advisory x_refsource_misc
https://discuss.hashicorp.com/t/hcsec-2021-22-consul-raft-rpc-privilege-escalation/29024
Third Party Advisory vendor-advisory
x_refsource_gentoo
https://security.gentoo.org/glsa/202207-01
Scores
CVSS v3
8.8
EPSS
0.0043
EPSS Percentile
62.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-295
Status
published
Products (2)
hashicorp/consul
< 1.8.15 (2 CPE variants)
hashicorp/consul
1.10.1 - 1.10.2Go
Published
Sep 07, 2021
Tracked Since
Feb 18, 2026