A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and lead to reflected XSS.
References
Configurations
Configuration 1 (hide)
|
History
10 Jan 2025, 13:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
08 Nov 2024, 15:49
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
| CWE | CWE-79 | |
| References | () https://discuss.hashicorp.com/t/hcsec-2024-24-consul-vulnerable-to-reflected-xss-on-content-type-error-manipulation - Vendor Advisory | |
| First Time |
Hashicorp consul
Hashicorp |
|
| CPE | cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:* cpe:2.3:a:hashicorp:consul:*:*:*:*:community:*:*:* |
30 Oct 2024, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-10-30 22:15
Updated : 2025-01-10 13:15
NVD link : CVE-2024-10086
Mitre link : CVE-2024-10086
JSON object : View
Products Affected
hashicorp
- consul
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
