CVE-2024-10086

Aliases:GHSA-99wr-c2px-grmhBIT-consul-2024-10086GO-2024-3242DEBIAN-CVE-2024-10086CGA-2c74-qj6f-pvfwCGA-2r2v-c9r3-f2cxCGA-3vxw-5fgg-96pfCGA-4mm6-r935-mv98CGA-4x7v-jcr2-qh4rCGA-4xhf-q4gj-w5cgCGA-52qx-3mfc-x6x7CGA-537j-qjmh-2q6pCGA-5fhq-qxqj-4qq4CGA-5h66-j2r8-fvmjCGA-5mgr-rpvw-gwrpCGA-5xp6-rjx2-c3f7CGA-634p-jh75-jg7wCGA-6v78-7r6x-f5g2CGA-73fw-748v-4p5hCGA-73j2-799x-cj4wCGA-7jfr-7chm-jpqpCGA-7jg9-rfr5-mg4xCGA-7jh9-xffc-qhp2CGA-7v6w-348j-64p2CGA-7vf9-98fc-q6w4CGA-98hh-gc3x-wvchCGA-9x94-gjrm-m493CGA-c7fg-gp5x-phhxCGA-cfcj-8qmg-8268CGA-cv7v-2fh9-xfg6CGA-f5fp-c8h2-hjfgCGA-f5rh-2244-r2xjCGA-fgmp-f6jr-89h6CGA-fmf7-7wjg-3pf2CGA-fmgr-p89c-87prCGA-g2m9-c5f4-fm6wCGA-g4v4-vxh9-qj84CGA-hq6v-jf6c-whcmCGA-jhfv-w7gc-3r62CGA-jx62-28qv-5c8pCGA-m6vx-vfww-98f2CGA-mf22-rpvh-pr6cCGA-mf2p-3jmx-cm6qCGA-mfc7-hvg9-x382CGA-mj9j-6fqc-g348CGA-p5h6-c4mw-4mc4CGA-prm3-v8vj-4752CGA-prxx-qhxj-cvrmCGA-rv3g-5vr7-fhjfCGA-rvwv-27g9-v7f7CGA-rw39-6f26-q6xrCGA-v3hg-g723-q8gjCGA-v96f-w9gm-cvrxCGA-wvr4-36qm-vm58CGA-x5h3-8pjw-fxv8CGA-x665-xx98-mqm3CGA-xq3m-rxwr-mg8wCGA-xr2f-2h6w-2hhg
Modified
Published: 30 Oct 2024, 21:21
Last modified:10 Jan 2025, 13:06

Vulnerability Summary

Overall Risk (default)
low
24/100
CVSS Score
6.1 MEDIUM
v3.1 (cve.org)
EPSS Score
0.42% LOW
0% probability -0.28%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Oct 2024, 21:21
Published
Vulnerability first disclosed
10 Jan 2025, 13:06
Last Modified
Vulnerability information updated

Description

A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and lead to reflected XSS.

CVSS Metrics

  • v4.0MEDIUMScore: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
  • v3.1MEDIUMScore: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS Trends

Current EPSS score: 0.42% Percentile: 36%

Techniques & Countermeasures

  • CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Affected Systems

  • chainguardconsul-1.18

    < 1.18.2-r44 | < 1.18.2-r48

  • chainguardconsul-1.19

    < 1.19.2-r47 | < 1.19.2-r43

  • chainguardconsul-1.20

    < 1.20.6-r11

  • chainguardconsul-1.20-oci-entrypoint

    < 1.20.6-r11

  • chainguardconsul-1.20-oci-entrypoint-compat

    < 1.20.6-r11

  • chainguardconsul-1.21

    < 1.21.5-r6

  • chainguardconsul-1.21-oci-entrypoint

    < 1.21.5-r6

  • chainguardconsul-1.21-oci-entrypoint-compat

    < 1.21.5-r6

  • chainguardconsul-1.22

    < 1.22.1-r2

  • chainguardconsul-1.22-oci-entrypoint

    < 1.22.1-r2

  • chainguardconsul-1.22-oci-entrypoint-compat

    < 1.22.1-r2

  • chainguardconsul-fips-1.19

    < 1.19.2-r42 | < 1.19.2-r47

  • chainguardconsul-fips-1.20

    < 1.20.6-r10

  • chainguardconsul-fips-1.20-oci-entrypoint

    < 1.20.6-r10

  • chainguardconsul-fips-1.20-oci-entrypoint-compat

    < 1.20.6-r10

  • chainguardconsul-fips-1.21

    < 1.21.5-r6

  • chainguardconsul-fips-1.21-oci-entrypoint

    < 1.21.5-r6

  • chainguardconsul-fips-1.21-oci-entrypoint-compat

    < 1.21.5-r6

  • chainguardconsul-fips-1.22

    < 1.22.2-r1

  • chainguardconsul-fips-1.22-oci-entrypoint

    < 1.22.2-r1

  • chainguardconsul-fips-1.22-oci-entrypoint-compat

    < 1.22.2-r1

  • debianconsul

    all

  • github.com/hashicorpconsul

    ≥ 1.4.1, < 1.20.0

  • hashicorpconsul

    ≥ 1.4.1, < 1.15.15 | ≥ 1.4.1, < 1.20.0 | ≥ 1.18.0, < 1.18.5 | ≥ 1.19.0, < 1.19.3

  • hashicorpconsul enterprise

    ≥ 1.4.1, < 1.20.0

References (9)