Skip to content
ConsulGHSA-h65h-v7fw-4p38

HashiCorp Consul Incorrect Access Control vulnerability

High7.5CVE-2019-12291 · Published Jun 9, 2023 · updated Aug 20, 2024

HashiCorp Consul 1.4.0 through 1.5.0 has Incorrect Access Control. Keys not matching a specific ACL rule used for prefix matching in a policy can be deleted by a token using that policy even with default deny settings configured. ### Specific Go Packages Affected github.com/hashicorp/consul/acl

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/consul
Go
>= 1.4.0, < 1.5.11.5.1
Details and references

More Consul advisories

All Consul
Advisory
Denial of service in HashiCorp Consul
High7.5Jan 31, 2024
Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers
High7.4Aug 9, 2023
Hashicorp Consul vulnerable to denial of service
Medium4.9Jun 3, 2023
Hashicorp Consul allows user with service:write permissions to patch remote proxy instances
High8.7Jun 3, 2023
Consul Server Panic when Ingress and API Gateways Configured with Peering Connections
Medium6.5Mar 9, 2023
Missing Authorization in HashiCorp Consul
High7.5Nov 16, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.