CVE-2020-7955 – github.com/hashicorp/consul
Package
Manager: go
Name: github.com/hashicorp/consul
Vulnerable Version: >=1.4.1 <1.6.3
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00311 pctl0.5365
Details
Incorrect Authorization in HashiCorp Consul HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resulting in potential unintended information disclosure. Fixed in 1.6.3.
Metadata
Created: 2021-07-28T17:57:57Z
Modified: 2021-07-27T15:08:01Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/07/GHSA-r9w6-rhh9-7v53/GHSA-r9w6-rhh9-7v53.json
CWE IDs: ["CWE-863"]
Alternative ID: GHSA-r9w6-rhh9-7v53
Finding: F006
Auto approve: 1