CVE-2021-36213: Security Misconfiguration
(updated )
HashiCorp Consul and Consul Enterprise default deny policy with a single L7 application-aware intention deny action cancels out, causing the intention to incorrectly fail open, allowing L4 traffic.
References
Detect and mitigate CVE-2021-36213 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →