Impact
Consul Community Edition and Consul Enterprise versions 1.20.1 through 2.0.2 are vulnerable to a Layer 7 intention authorization bypass that occurs when a service proxy is configured with a custom public listener. The flaw permits an authenticated mesh workload to reach HTTP paths that are normally blocked by a path‑based deny intention. This bypass removes the intention layer for selected traffic, allowing access to resources that the intention was intended to protect. The weakness is identified as CWE‑551 and CWE‑647.
Affected Systems
HashiCorp Consul Community Edition and HashiCorp Consul Enterprise, affected from version 1.20.1 through 2.0.2. The vulnerability is fixed in Consul 2.0.3 and in Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Risk and Exploitability
The CVSS score of 4.2 indicates a moderate risk. The EPSS score is less than 1%, signaling a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The attack requires that a custom public listener be configured on a service proxy; the CVE description does not specify the privileges needed for this configuration, so it is unclear whether administrative access is required. The impact is limited to unauthorized access to the protected HTTP paths, with no mention of exploitation of confidentiality or integrity in the CVE description.
OpenCVE Enrichment