Improper access control in Consul Enterprise - CVE-2023-2816
Published: June 8, 2023
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in Lua extension. A remote user with service:write ACL permissions for an upstream service can modify Envoy proxy config for downstream services without equivalent permissions for those services.
Affected software
Gentoo Linux
app-admin/consul
How to mitigate CVE-2023-2816
app-admin/consul - update to 1.15.10