Impact
Consul Community Edition and Consul Enterprise versions 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass that occurs when a service proxy is configured with a custom public listener. The flaw allows an authenticated mesh workload to reach HTTP paths that are normally blocked by a path‑based deny intention, giving unauthorized access to restricted resources and potentially exposing sensitive data or allowing integrity violations. The vulnerability is categorized as CWE‑647, reflecting a flaw that grants access that should be denied.
Affected Systems
HashiCorp Consul Community Edition and HashiCorp Consul Enterprise, specifically versions 1.20.1 through 2.0.2, are impacted. The fix is included in Consul 2.0.3 and for Enterprise in versions 1.21.17, 1.22.11, and 2.0.3.
Risk and Exploitability
The CVSS score of 4.2 indicates a moderate risk level. EPSS data is currently unavailable, and the vulnerability is not listed in CISA’s known exploited vulnerabilities catalog. The likely attack vector involves configuring a custom public listener, so the exploitation requires administrative access to service proxy settings. Evidence shows that an authenticated mesh workload can bypass intention rules, highlighting the need for remediation before a broader threat surface emerges.
OpenCVE Enrichment