Improper access control in Consul Enterprise - CVE-2023-2816
Published: June 8, 2023
Consul Enterprise
HashiCorp
Description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in Lua extension. A remote user with service:write ACL permissions for an upstream service can modify Envoy proxy config for downstream services without equivalent permissions for those services.