VDB

CVE-2021-36213

CVE-2021-36213 PUBLISHED

HashiCorp Consul and Consul Enterprise 1.9.0 through 1.10.0 default deny policy with a single L7 application-aware intention deny action cancels out, causing the intention to incorrectly fail open, allowing L4 traffic. Fixed in 1.9.8 and 1.10.1.

EPSS 0.77% · 73.7th percentile

Risk Scores

EPSS Score
0.77%
73.7th percentile

Affected Products

VendorProductVersions
Bitnamiconsul1.9.0, 1.10.0, 1.10.0
Bitnamiconsul1.10.0, 1.9.0

Timeline

  • Jul 17, 2021 CVE Published
  • Jul 18, 2021 EPSS Score
  • Sep 15, 2021 EPSS Score
  • Nov 14, 2021 EPSS Score
  • Jan 12, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 13, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Jul 10, 2022 EPSS Score
  • Sep 8, 2022 EPSS Score
  • Sep 14, 2022 CVE Updated
  • Nov 7, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›