Database/Control plane, storage & DevOps
HashiCorp Consul: Missing Content-Type header lets user input be reinterpreted
CVSS 6.1CVE-2024-10086Control plane, storage & DevOpscurated
Impact
Missing Content-Type header lets user input be reinterpreted -> reflected XSS on the Consul UI
Who can reach it
Network (remote)
What to do
Control-plane: upgrade; keep the Consul UI behind the ops VPN
References
Related entries
- HashiCorp Consul: Internal RPC endpoint does not check multiple SAN URIs in a CSRCVE-2022-40716 · HashiCorp ConsulMedium
- SPI flash configuration (flash descriptor / protected range registers) across multiple Intel platformsCVE-2017-5703 · SPI flash configuration (flash descriptor / protected range registers) across multiple Intel platformsMedium
- Intel Data Center GPU Max Series 1100 / 1550: An improper conditions check lets a privileged local user takeCVE-2023-47165 · Intel Data Center GPU Max Series 1100 / 1550Medium
- AMD PCIe link handling (memory buffer bounds): A guest VM can drive the PCIe link into an out-of-bounds conditionCVE-2024-21961 · AMD PCIe link handling (memory buffer bounds)Medium
- OpenStack Swift: S3API does not strip X-Copy-From, allowing cross-tenant object readsCVE-2026-71192 · OpenStack Swift S3API middleware (X-Copy-From header handling with s3_acl=true)Medium
- AMD NBIO register lock bits - MMIO routing configuration: The sibling of the SMN issue: unprotected NBIO lock bits letCVE-2025-61971 · AMD NBIO register lock bits - MMIO routing configurationMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.