GHSA-rqjq-ww83-wv5c
GitHub Security Advisory
Hashicorp Consul allows user with service:write permissions to patch remote proxy instances
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has permission to modify the service(s) corresponding to those modified proxies.
Affected Packages
Go
github.com/hashicorp/consul
Affected versions:
1.15.0
(fixed in 1.15.3)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 6, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.