Impact
Consul and Consul Enterprise allow a service to communicate with subjects it should not be allowed to reach due to inadequate escaping of service names, namespaces, and partitions when constructing Envoy RBAC rules for Connect intentions. The flaw enables an attacker who can influence the service mesh to have unauthorized access to service endpoints, potentially compromising confidentiality and availability of internal services.
Affected Systems
HashiCorp Consul and HashiCorp Consul Enterprise are affected. The vulnerability applies to all versions prior to Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12, and 2.0.4, which contain the fix. Users running any earlier releases should verify their version and consider upgrading.
Risk and Exploitability
The CVSS score of 7.5 indicates moderate to high risk. The EPSS score is not available, so the exploitation probability is uncertain, but the fact that the flaw enables bypass of the Connect service mesh suggests that an attacker with access to services in the cluster could abuse it. It is likely that the attack vector is internal or involves a compromised service, inferred from the required ability to generate or manipulate RBAC rules. The vulnerability is not listed in the CISA KEV catalog, but the impact to internal service communication warrants prioritization.
OpenCVE Enrichment