CVE-2022-40716
MEDIUMHashiCorp Consul <1.11.8-1.13.1 - Privilege Escalation
Title source: llmDescription
HashiCorp Consul and Consul Enterprise up to 1.11.8, 1.12.4, and 1.13.1 do not check for multiple SAN URI values in a CSR on the internal RPC endpoint, enabling leverage of privileged access to bypass service mesh intentions. Fixed in 1.11.9, 1.12.5, and 1.13.2."
References (5)
Scores
CVSS v3
6.5
EPSS
0.0036
EPSS Percentile
57.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Classification
CWE
CWE-252
Status
published
Affected Products (3)
hashicorp/consul
< 1.11.9
hashicorp/consul
< 1.11.9
hashicorp/consul
< 1.11.9Go
Timeline
Published
Sep 23, 2022
Tracked Since
Feb 18, 2026