A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and lead to reflected XSS.
{
"versions": [
{
"introduced": "1.4.1"
},
{
"fixed": "1.15.15"
},
{
"introduced": "1.4.1"
},
{
"fixed": "1.20.0"
},
{
"introduced": "1.18.0"
},
{
"fixed": "1.18.5"
},
{
"introduced": "1.19.0"
},
{
"fixed": "1.19.3"
}
]
}