CVE-2021-38698 log

Source
Severity Medium
Remote Yes
Type Information disclosure
Description
In HashiCorp Consul before version 1.10.2, the Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic.
Group Package Affected Fixed Severity Status Ticket
AVG-2360 consul 1.10.1-1 1.10.2-1 High Fixed
References
https://discuss.hashicorp.com/t/hcsec-2021-24-consul-missing-authorization-check-on-txn-apply-endpoint/29026