Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3020 | A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using URL paths in L7 traffic intentions could bypass HTTP request path-based access rules. |
Github GHSA |
GHSA-chgm-7r52-whjj | Hashicorp Consul Path Traversal vulnerability |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 10 Jan 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 12 Nov 2024 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
threat_severity
|
threat_severity
|
Fri, 08 Nov 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:* cpe:2.3:a:hashicorp:consul:1.20.0:*:*:*:enterprise:*:*:* |
Fri, 01 Nov 2024 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 31 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hashicorp
Hashicorp consul |
|
| CPEs | cpe:2.3:a:hashicorp:consul:*:*:*:*:community:*:*:* cpe:2.3:a:hashicorp:consul:-:*:*:*:enterprise:*:*:* |
|
| Vendors & Products |
Hashicorp
Hashicorp consul |
|
| Metrics |
ssvc
|
Wed, 30 Oct 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using URL paths in L7 traffic intentions could bypass HTTP request path-based access rules. | |
| Title | Consul L7 Intentions Vulnerable To URL Path Bypass | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2025-01-10T13:06:39.935Z
Reserved: 2024-10-15T17:46:30.633Z
Link: CVE-2024-10005
Updated: 2025-01-10T13:06:39.935Z
Status : Modified
Published: 2024-10-30T22:15:02.820
Modified: 2025-01-10T13:15:08.223
Link: CVE-2024-10005
OpenCVE Enrichment
No data.
EUVD
Github GHSA