Skip to content
ConsulGHSA-p2j5-3f4c-224r

Improper Input Validation in HashiCorp Consul

Medium5.3CVE-2020-13170 · Published May 18, 2021 · updated Aug 21, 2024

HashiCorp Consul and Consul Enterprise did not appropriately enforce scope for local tokens issued by a primary data center, where replication to a secondary data center was not enabled. Introduced in 1.4.0, fixed in 1.6.6 and 1.7.4. ### Specific Go Packages Affected github.com/hashicorp/consul/agent

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/consul
Go
>= 1.6.0-beta1, < 1.6.61.6.6
>= 1.7.0, < 1.7.41.7.4
Details and references

More Consul advisories

All Consul
Advisory
Incorrect Authorization in HashiCorp Consul
Medium5.3Jul 28, 2021
HashiCorp Consul L7 deny intention results in an allow action
High7.5Jul 19, 2021
Hashicorp Consul Missing SSL Certificate Validation
High7.5Jul 19, 2021
Incorrect Permission Assignment for Critical Resource in Hashicorp Consul
Medium5.3Jun 23, 2021
Allocation of Resources Without Limits or Throttling in Hashicorp Consul
High7.5May 18, 2021
Denial of Service (DoS) in HashiCorp Consul
High7.5May 18, 2021

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.