logo

CVE-2020-7955 github.com/hashicorp/consul

Package

Manager: go
Name: github.com/hashicorp/consul
Vulnerable Version: >=1.4.1 <1.6.3

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00311 pctl0.5365

Details

Incorrect Authorization in HashiCorp Consul HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resulting in potential unintended information disclosure. Fixed in 1.6.3.

Metadata

Created: 2021-07-28T17:57:57Z
Modified: 2021-07-27T15:08:01Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/07/GHSA-r9w6-rhh9-7v53/GHSA-r9w6-rhh9-7v53.json
CWE IDs: ["CWE-863"]
Alternative ID: GHSA-r9w6-rhh9-7v53
Finding: F006
Auto approve: 1