{"id":"CVE-2024-10006","title":"hashicorp/consul: consul: Consul L7 Intentions Vulnerable To Headers Bypass (CVE-2024-10006)","summary":"A flaw was found in HashiCorp Consul and Consul Enterprise. The server response does not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and can lead to reflected cross-site scripting (XSS).","severity":"high","cvss":8.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L","cvssSource":"vendor","cwe":"CWE-644","vendor":"Red Hat","product":"Red Hat OpenShift Dev Spaces (RHOSDS) 3.23","affected":["openshift_dev_spaces_rhosds 3.23"],"patched":["openshift_dev_spaces_rhosds 3.23"],"published":"2024-10-30","updated":"2026-09-21","sourceUpdated":"2026-09-21T15:04:25+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-10006.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-10006.json"},{"url":"https://access.redhat.com/security/cve/CVE-2024-10006"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2322858"},{"url":"https://www.cve.org/CVERecord?id=CVE-2024-10006"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-10006"},{"url":"https://discuss.hashicorp.com/t/hcsec-2024-23-consul-l7-intentions-vulnerable-to-headers-bypass"},{"url":"https://access.redhat.com/errata/RHSA-2025:15847"},{"url":"https://github.com/hashicorp/consul/pull/21816"},{"url":"https://github.com/hashicorp/consul/commit/d9206fc7e284a9244af4d62f8653a63ca30bd00c"},{"url":"https://github.com/hashicorp/consul"},{"url":"https://security.netapp.com/advisory/ntap-20250110-0005"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.00467,"epssPercentile":0.37736,"aliases":["GHSA-5c4w-8hhh-3c3h","BIT-consul-2024-10006","GO-2024-3241"],"ecosystem":"go","ingestedAt":"2026-09-12T03:13:01.755Z","slug":"CVE-2024-10006","body":"## Overview\n\nA flaw was found in HashiCorp Consul and Consul Enterprise. The server response does not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and can lead to reflected cross-site scripting (XSS).\n\n## Vendor advisories\n\n- **RHSA-2025:15847** · Red Hat · fixed in: Red Hat OpenShift Dev Spaces (RHOSDS) 3.23 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15847)\n\n**hashicorp/consul: consul: Consul L7 Intentions Vulnerable To Headers Bypass** — rated Important by Red Hat. Released 2024-10-30, updated 2026-09-21.\n\nFixed:\n\n- Red Hat OpenShift Dev Spaces (RHOSDS) 3.23\n\nNot affected:\n\n- Red Hat OpenShift Dev Spaces (RHOSDS) 3.23\n\n## Remediation\n\nBefore applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:15847\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.\n\n## Package advisory (CVE-2024-10006)\n\nAffected packages:\n\n- `github.com/hashicorp/consul >= 1.9.0, < 1.20.1`\n\nPatched in:\n\n- `github.com/hashicorp/consul 1.20.1`\n\nSource: https://osv.dev/vulnerability/GHSA-5c4w-8hhh-3c3h","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":45.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}