« Volver al listado

CVE-2024-10086

Estado: ModificadaMedia (6.1)—

A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and lead to reflected XSS.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-10086",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-10086",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-31T13:49:16.403136Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@hashicorp.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@hashicorp.com",
      "affectedData": [
        {
          "repo": "https://github.com/hashicorp/consul",
          "vendor": "HashiCorp",
          "product": "Consul",
          "versions": [
            {
              "status": "affected",
              "version": "1.4.1",
              "lessThan": "1.20.0",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "64 bit",
            "32 bit",
            "x86",
            "ARM",
            "MacOS",
            "Windows",
            "Linux"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://github.com/hashicorp/consul",
          "vendor": "HashiCorp",
          "product": "Consul Enterprise",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "1.19.3",
                  "status": "unaffected"
                },
                {
                  "at": "1.18.5",
                  "status": "unaffected"
                },
                {
                  "at": "1.15.15",
                  "status": "unaffected"
                }
              ],
              "version": "1.4.1",
              "lessThan": "1.20.0",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "64 bit",
            "32 bit",
            "x86",
            "ARM",
            "MacOS",
            "Windows",
            "Linux"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-10-30T22:15:03.283",
  "references": [
    {
      "url": "https://discuss.hashicorp.com/t/hcsec-2024-24-consul-vulnerable-to-reflected-xss-on-content-type-error-manipulation",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@hashicorp.com"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20250110-0006/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@hashicorp.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and lead to reflected XSS."
    },
    {
      "lang": "es",
      "value": "Se identificó una vulnerabilidad en Consul y Consul Enterprise tal que la respuesta del servidor no establecía explícitamente un encabezado HTTP Content-Type, lo que permitía que las entradas proporcionadas por el usuario se malinterpretaran y generaran un XSS reflejado."
    }
  ],
  "lastModified": "2026-06-17T06:54:53.027",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F9B18D72-3819-4927-AF49-239668B4719D",
              "versionEndExcluding": "1.15.15",
              "versionStartIncluding": "1.4.1"
            },
            {
              "criteria": "cpe:2.3:a:hashicorp:consul:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6471636F-7182-4F2D-B80E-25D46AE453F2",
              "versionEndExcluding": "1.20.0",
              "versionStartIncluding": "1.4.1"
            },
            {
              "criteria": "cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "36CDCEB8-8B22-4290-9071-81CE3F0F6B95",
              "versionEndExcluding": "1.18.5",
              "versionStartIncluding": "1.18.0"
            },
            {
              "criteria": "cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0AB043DB-FC48-4DE7-80BA-EC410ECD44F2",
              "versionEndExcluding": "1.19.3",
              "versionStartIncluding": "1.19.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@hashicorp.com"
}