Skip to content
ConsulGHSA-hwqm-x785-qh8p

Incorrect Permission Assignment for Critical Resource in Hashicorp Consul

Medium5.3CVE-2020-12797 · Published Jun 23, 2021 · updated Aug 21, 2024

HashiCorp Consul and Consul Enterprise failed to enforce changes to legacy ACL token rules due to non-propagation to secondary data centers. Introduced in 1.4.0, fixed in 1.6.6 and 1.7.4. ### Specific Go Packages Affected github.com/hashicorp/consul/agent/structs

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/consul
Go
>= 1.6.0, < 1.6.61.6.6
>= 1.7.0, < 1.7.41.7.4
Details and references

More Consul advisories

All Consul
Advisory
Incorrect Authorization in HashiCorp Consul
Medium5.3Jul 28, 2021
HashiCorp Consul L7 deny intention results in an allow action
High7.5Jul 19, 2021
Hashicorp Consul Missing SSL Certificate Validation
High7.5Jul 19, 2021
Allocation of Resources Without Limits or Throttling in Hashicorp Consul
High7.5May 18, 2021
Improper Input Validation in HashiCorp Consul
Medium5.3May 18, 2021
Denial of Service (DoS) in HashiCorp Consul
High7.5May 18, 2021

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.