Miggo Logo

CVE-2021-37219: HashiCorp Consul Privilege Escalation Vulnerability

8.8

CVSS Score
3.1

Basic Information

EPSS Score
0.85498%
Published
9/8/2021
Updated
4/3/2023
KEV Status
No
Technology
TechnologyGo

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
github.com/hashicorp/consulgo= 1.10.11.10.2
github.com/hashicorp/consulgo>= 1.9.0, < 1.9.91.9.9
github.com/hashicorp/consulgo< 1.8.151.8.15

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

**s*i*orp *onsul *n* *onsul *nt*rpris* *.**.* R**t RP* l*y*r *llows non-s*rv*r ***nts wit* * v*li* **rti*i**t* si*n** *y t** s*m* ** to ****ss s*rv*r-only *un*tion*lity, *n**lin* privil*** *s**l*tion. *ix** in *.*.**, *.*.* *n* *.**.*.

Reasoning

No *n*lysis *v*il**l*