ConsulGHSA-h65h-v7fw-4p38
HashiCorp Consul Incorrect Access Control vulnerability
High7.5CVE-2019-12291 · Published Jun 9, 2023 · updated Aug 20, 2024
HashiCorp Consul 1.4.0 through 1.5.0 has Incorrect Access Control. Keys not matching a specific ACL rule used for prefix matching in a policy can be deleted by a token using that policy even with default deny settings configured. ### Specific Go Packages Affected github.com/hashicorp/consul/acl
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/consul Go | >= 1.4.0, < 1.5.1 | 1.5.1 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-284
- Also known as
- CVE-2019-12291, GO-2023-1852
More Consul advisories
All Consul| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jan 312024 | Denial of service in HashiCorp Consul | High7.5 | 1.7.9+1 more |
| Aug 92023 | Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers | High7.4 | 1.16.1 |
| Jun 32023 | Hashicorp Consul vulnerable to denial of service | Medium4.9 | 1.14.5+1 more |
| Jun 32023 | Hashicorp Consul allows user with service:write permissions to patch remote proxy instances | High8.7 | 1.15.3 |
| Mar 92023 | Consul Server Panic when Ingress and API Gateways Configured with Peering Connections | Medium6.5 | 1.14.5 |
| Nov 162022 | Missing Authorization in HashiCorp Consul | High7.5 | 1.14.0 |