ConsulGHSA-r9w6-rhh9-7v53
Incorrect Authorization in HashiCorp Consul
Medium5.3CVE-2020-7955 · Published Jul 28, 2021 · updated Aug 21, 2024
HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resulting in potential unintended information disclosure. Fixed in 1.6.3.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/consul Go | >= 1.4.1, < 1.6.3 | 1.6.3 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-863
- Also known as
- BIT-consul-2020-7955, CVE-2020-7955, GO-2022-0874
More Consul advisories
All Consul| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 82021 | Consul: missing authorization | Medium6.5 | 1.8.15+2 more |
| Sep 82021 | HashiCorp Consul Privilege Escalation Vulnerability | High8.8 | 1.8.15+2 more |
| Jul 192021 | HashiCorp Consul L7 deny intention results in an allow action | High7.5 | 1.10.1 |
| Jul 192021 | Hashicorp Consul Missing SSL Certificate Validation | High7.5 | 1.10.1 |
| Jun 232021 | Incorrect Permission Assignment for Critical Resource in Hashicorp Consul | Medium5.3 | 1.6.6+1 more |
| May 182021 | Allocation of Resources Without Limits or Throttling in Hashicorp Consul | High7.5 | 1.6.6+1 more |