Authentication mechanism absence or evasion In github.com/hashicorp/consul
Description
Incorrect Authorization in HashiCorp Consul HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resulting in potential unintended information disclosure. Fixed in 1.6.3.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 1.6.3 | ||
debian 11 | 1.7.0+dfsg1-1 | ||
go | v1.6.2 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3.