A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.
{ "cpes": [ "cpe:2.3:a:hashicorp:consul:*:*:*:*:*:*:*:*", "cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*", "cpe:2.3:a:hashicorp:consul:*:*:*:*:*:go:*:*", "cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:go:*:*" ], "severity": "High" }