CVE-2023-2816
Consul Envoy Extension Downsteam Proxy Configuration By Upstream Service Owner
8.7
HIGH
CVSS 3.1
EPSS 0.18%
Description
Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has permission to modify the service(s) corresponding to those modified proxies.
How to fix CVE-2023-2816
To remediate CVE-2023-2816, upgrade the affected package to a fixed version below.
- —upgrade to 1.15.3 or later
- —upgrade to 1.15.3 or later
- —upgrade to 1.15.3 or later
Is CVE-2023-2816 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- >= 1.15.0, < 1.15.3
- >= 1.15.0, < 1.15.3
- >= 1.15.0, < 1.15.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.7 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N |