Improper authorization control for web services In consul

Description

Incorrect Permission Assignment for Critical Resource in Hashicorp Consul HashiCorp Consul and Consul Enterprise failed to enforce changes to legacy ACL token rules due to non-propagation to secondary data centers. Introduced in 1.4.0, fixed in 1.6.6 and 1.7.4.

Specific Go Packages Affected

github.com/hashicorp/consul/agent/structs

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions