CVE-2021-37219 is a high-severity privilege escalation vulnerability affecting HashiCorp Consul and Consul Enterprise versions up to 1.10.1. It allows non-server agents with a valid CA-signed certificate to access server-only functionality within the Raft RPC layer. This network-based vulnerability has low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. While no active exploitation or public exploit code has been identified, and community discussion is minimal, organizations using affected versions should prioritize patching to versions 1.8.15, 1.9.9, or 1.10.2.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.15CPE matchmatch criteria | cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:* | ||
< 1.8.15CPE matchmatch criteria | cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:* | ||
>= 1.9.0, < 1.9.9CPE matchmatch criteria | cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:* | ||
>= 1.9.0, < 1.9.9CPE matchmatch criteria | cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:* | ||
>= 1.10.0, < 1.10.2CPE matchmatch criteria | cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.