Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2948 | A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules. |
Github GHSA |
GHSA-5c4w-8hhh-3c3h | Hashicorp Consul Improper Neutralization of HTTP Headers for Scripting Syntax vulnerability |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 10 Jan 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 08 Nov 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-116 | |
| CPEs | cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:* cpe:2.3:a:hashicorp:consul:1.20.0:*:*:*:enterprise:*:*:* |
Fri, 01 Nov 2024 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 31 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hashicorp
Hashicorp consul |
|
| CPEs | cpe:2.3:a:hashicorp:consul:*:*:*:*:community:*:*:* cpe:2.3:a:hashicorp:consul:-:*:*:*:enterprise:*:*:* |
|
| Vendors & Products |
Hashicorp
Hashicorp consul |
|
| Metrics |
ssvc
|
Wed, 30 Oct 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules. | |
| Title | Consul L7 Intentions Vulnerable To Headers Bypass | |
| Weaknesses | CWE-644 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2025-01-10T13:06:41.296Z
Reserved: 2024-10-15T17:46:48.500Z
Link: CVE-2024-10006
Updated: 2025-01-10T13:06:41.296Z
Status : Modified
Published: 2024-10-30T22:15:03.063
Modified: 2025-01-10T13:15:08.440
Link: CVE-2024-10006
OpenCVE Enrichment
No data.
EUVD
Github GHSA