CVE-2022-40716

MEDIUM

HashiCorp Consul <1.11.8-1.13.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

HashiCorp Consul and Consul Enterprise up to 1.11.8, 1.12.4, and 1.13.1 do not check for multiple SAN URI values in a CSR on the internal RPC endpoint, enabling leverage of privileged access to bypass service mesh intentions. Fixed in 1.11.9, 1.12.5, and 1.13.2."

Scores

CVSS v3 6.5
EPSS 0.0036
EPSS Percentile 58.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-252
Status published
Products (2)
hashicorp/consul < 1.11.9 (2 CPE variants)
hashicorp/consul 0 - 1.11.9Go
Published Sep 23, 2022
Tracked Since Feb 18, 2026