Skip to content
ConsulGHSA-r9w6-rhh9-7v53

Incorrect Authorization in HashiCorp Consul

Medium5.3CVE-2020-7955 · Published Jul 28, 2021 · updated Aug 21, 2024

HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resulting in potential unintended information disclosure. Fixed in 1.6.3.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/consul
Go
>= 1.4.1, < 1.6.31.6.3
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-863
Also known as
BIT-consul-2020-7955, CVE-2020-7955, GO-2022-0874

More Consul advisories

All Consul
Advisory
Consul: missing authorization
Medium6.5Sep 8, 2021
HashiCorp Consul Privilege Escalation Vulnerability
High8.8Sep 8, 2021
HashiCorp Consul L7 deny intention results in an allow action
High7.5Jul 19, 2021
Hashicorp Consul Missing SSL Certificate Validation
High7.5Jul 19, 2021
Incorrect Permission Assignment for Critical Resource in Hashicorp Consul
Medium5.3Jun 23, 2021
Allocation of Resources Without Limits or Throttling in Hashicorp Consul
High7.5May 18, 2021

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.