CVE-2021-41803
Consul vulnerability analysis and mitigation

Overview

HashiCorp Consul versions 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 contain a vulnerability in the auto-config feature that allows specially crafted requests to generate TLS certificates and ACL tokens for unintended node names. The vulnerability was discovered internally by the Consul engineering team and was fixed in versions 1.11.9, 1.12.5, and 1.13.2 (HashiCorp Discuss).

Technical details

The vulnerability affects Consul's auto-config feature, which enables distribution of security material and configuration settings to Consul agents in a datacenter. The issue stems from improper validation of node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC. Client agents use JSON web tokens (JWTs) to securely retrieve gossip encryption keys, TLS certificates, ACL settings, and other configuration properties from server agents (HashiCorp Discuss).

Impact

An attacker could craft specific auto-config requests that would allow TLS certificates and ACL tokens to be generated for node names not intended by the operator. This forces Consul to store unintended information, which can be repeatedly abused to cause an authenticated denial of service attack from a malicious operator (HashiCorp Discuss).

Mitigation and workarounds

Organizations using affected versions of Consul, particularly those using the auto-config feature, should upgrade to the fixed versions: Consul 1.11.9, 1.12.5, 1.13.2, or newer. No alternative workarounds have been provided (HashiCorp Discuss).

Additional resources


SourceThis report was generated using AI

Related Consul vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-11375MEDIUM6.5
  • ConsulConsul
  • consul-fips-1.19
NoYesOct 28, 2025
CVE-2025-11374MEDIUM6.5
  • ConsulConsul
  • cpe:2.3:a:hashicorp:consul
NoYesOct 28, 2025
CVE-2024-10086MEDIUM6.1
  • ConsulConsul
  • consul
NoYesOct 30, 2024
CVE-2024-10006MEDIUM5.8
  • ConsulConsul
  • consul-1.21
NoYesOct 30, 2024
CVE-2024-10005MEDIUM5.8
  • ConsulConsul
  • consul-fips-1.21
NoYesOct 30, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management