HashiCorp Consul and Consul Enterprise 1.16.0 when using JWT Auth for service mesh incorrectly allows/denies access regardless of service identities. Fixed in 1.16.1.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "1.16.0"
},
{
"introduced": "0"
},
{
"last_affected": "1.16.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.16.0-rc1"
}
]
}