Bug 2189788 (CVE-2021-41803)

Summary: CVE-2021-41803 consul: Consul Auto-Config JWT Authorization Missing Input Validation
Product: [Other] Security Response Reporter: Avinash Hanwate <ahanwate>
Component: vulnerabilityAssignee: Nobody <nobody>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: amctagga, dfreiber, gparvin, jburrell, jcantril, nboldt, njean, owatkins, pahickey, rogbas, scorneli, stcannon, teagle, vkumar
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Consul 1.11.9, Consul 1.12.5, Consul 1.13.2 Doc Type: ---
Doc Text:
A flaw was found in HashiCorp Consul, where it is vulnerable to a denial of service caused by improper input validation for the node or segment names. By sending a specially-crafted request, a remote, authenticated attacker can cause a denial of service.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2189789, 2189790, 2189791, 2189792, 2189793, 2189794    
Bug Blocks: 2189661    

Description Avinash Hanwate 2023-04-26 07:51:27 UTC
HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC. Fixed in 1.11.9, 1.12.5, and 1.13.2."

https://www.hashicorp.com/blog/category/consul
https://discuss.hashicorp.com/t/hcsec-2022-19-consul-auto-config-jwt-authorization-missing-input-validation/44627

Comment 1 Avinash Hanwate 2023-04-26 07:55:36 UTC
Created golang-github-hashicorp-consul tracking bugs for this issue:

Affects: fedora-all [bug 2189790]


Created golang-github-hashicorp-consul-api tracking bugs for this issue:

Affects: fedora-all [bug 2189791]


Created golang-github-hashicorp-consul-sdk tracking bugs for this issue:

Affects: fedora-all [bug 2189792]


Created moby-engine tracking bugs for this issue:

Affects: fedora-all [bug 2189789]