← Back

CVE-2024-10086

nvd nist
Published: Oct 30, 2024Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and lead to reflected XSS.

Affected (4)

Products: Hashicorp: Consul
1 product
Consul
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Hashicorp
From 1.4.1 to 1.20.0
From 1.18.0 to 1.18.5
From 1.19.0 to 1.19.3
From 1.4.1 to 1.15.15

Timeline

No history available yet.