CVE-2021-32574 log

Source
Severity Low
Remote Yes
Type Certificate verification bypass
Description
HashiCorp Consul before version 1.9.8 does not validate SSL certificates correctly: xds does not ensure that the Subject Alternative Name of an upstream is validated.
Group Package Affected Fixed Severity Status Ticket
AVG-2171 consul 1.9.7-1 1.9.8-1 Medium Fixed
Date Advisory Group Package Severity Type
27 Jul 2021 ASA-202107-69 AVG-2171 consul Medium multiple issues
References
https://discuss.hashicorp.com/t/hcsec-2021-17-consul-s-envoy-tls-configuration-did-not-validate-destination-service-subject-alternative-names/26856
https://github.com/hashicorp/consul/issues/6364
https://github.com/hashicorp/consul/pull/10621
https://github.com/hashicorp/consul/pull/10623
https://github.com/hashicorp/consul/commit/2bca52fa88caedc2b6a7cc3627f3cd1f683c6d74
https://github.com/hashicorp/consul/commit/0b4fe4b7a2a7c400521248a0d548429963f4c614