{"id":"CVE-2021-38698","aliases":["BIT-consul-2021-38698","GHSA-6hw5-6gcx-phmw","GO-2022-0559"],"url":"https://o3.security/vulnerability/CVE-2021-38698","summary":"HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic.","details":"HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic. Fixed in 1.8.15, 1.9.9 and 1.10.2.","published":"2021-09-07T12:15:07.930Z","modified":"2026-07-09T05:14:21.170811Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/hashicorp/consul","fixedVersion":"1.10.2"},{"ecosystem":"Go","name":"github.com/hashicorp/consul","fixedVersion":"1.9.9"},{"ecosystem":"Go","name":"github.com/hashicorp/consul","fixedVersion":"1.8.15"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://discuss.hashicorp.com/t/hcsec-2021-24-consul-missing-authorization-check-on-txn-apply-endpoint/29026"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202208-09"},{"type":"ADVISORY","url":"https://www.hashicorp.com/blog/category/consul"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T05:14:21.170811Z"}}