Lack of data validation In github.com/hashicorp/consul
Description
Improper Input Validation in HashiCorp Consul HashiCorp Consul and Consul Enterprise did not appropriately enforce scope for local tokens issued by a primary data center, where replication to a secondary data center was not enabled. Introduced in 1.4.0, fixed in 1.6.6 and 1.7.4.
Specific Go Packages Affected
github.com/hashicorp/consul/agent
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 1.6.6, 1.7.4 | ||
debian 11 | 1.7.4+dfsg1-1 | ||
go | v1.6.6, v1.7.4 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4.