CVE-2023-2816

HIGH

Consul 1.15.0-1.15.3 - Incorrect Privilege Assignment via Envoy Extension Downstream Proxy Configuration

Title source: llm
STIX 2.1

Description

Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has permission to modify the service(s) corresponding to those modified proxies.

Scores

CVSS v3 8.7
EPSS 0.0016
EPSS Percentile 36.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-266
Status published
Products (2)
hashicorp/consul 1.15.0 - 1.15.3 (2 CPE variants)
hashicorp/consul 1.15.0 - 1.15.3Go
Published Jun 02, 2023
Tracked Since Feb 18, 2026