Improper authorization control for web services In github.com/hashicorp/consul/acl
Description
HashiCorp Consul Incorrect Access Control vulnerability HashiCorp Consul 1.4.0 through 1.5.0 has Incorrect Access Control. Keys not matching a specific ACL rule used for prefix matching in a policy can be deleted by a token using that policy even with default deny settings configured.
Specific Go Packages Affected
github.com/hashicorp/consul/acl
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | v1.5.1 | ||
go | 1.5.1 | ||
debian 11 | 1.4.5+dfsg1-1 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3.