JWT Auth in L7 Intentions Allow For Mismatched Service Identity and JWT Providers for Access
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.4epss 0.4%
exploitation probability
0.4%top 62% of all CVEs
observed exploitation
nono source reports it
HashiCorp Consul and Consul Enterprise 1.16.0 when using JWT Auth for service mesh incorrectly allows/denies access regardless of service identities. Fixed in 1.16.1.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L