Improper Authentication in Consul - CVE-2021-37219
Published: August 30, 2021
Vulnerability identifier: #VU56146
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-37219
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests. A remote attacker can use a specially crafted raft requests to bypass authentication process and gain unauthorized access to the application.
Affected software
Consul
Gentoo Linux
IBM Cloud Pak for Watson AIOps
Gentoo Linux
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2021-37219
Install updates from vendor's website.
Consul - addressed in versions 1.8.15, 1.9.9, 1.10.2
IBM Cloud Pak for Watson AIOps - update to 4.1.0
IBM Cloud Pak for Watson AIOps - update to 4.1.0