Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fhm8-cxcv-pwvc

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

HashiCorp Consul Access Restriction Bypass

HashiCorp Consul (and Consul Enterprise) 1.4.x before 1.4.3 allows a client to bypass intended access restrictions and obtain the privileges of one other arbitrary token within secondary datacenters, because a token with literally "" as its secret is used in unusual circumstances.

Пакеты

Наименование

github.com/hashicorp/consul

go
Затронутые версииВерсия исправления

>= 1.4.0, < 1.4.3

1.4.3

EPSS

Процентиль: 58%
0.00362
Низкий

8.1 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 7 лет назад

HashiCorp Consul (and Consul Enterprise) 1.4.x before 1.4.3 allows a client to bypass intended access restrictions and obtain the privileges of one other arbitrary token within secondary datacenters, because a token with literally "<hidden>" as its secret is used in unusual circumstances.

CVSS3: 8.1
nvd
почти 7 лет назад

HashiCorp Consul (and Consul Enterprise) 1.4.x before 1.4.3 allows a client to bypass intended access restrictions and obtain the privileges of one other arbitrary token within secondary datacenters, because a token with literally "<hidden>" as its secret is used in unusual circumstances.

CVSS3: 8.1
debian
почти 7 лет назад

HashiCorp Consul (and Consul Enterprise) 1.4.x before 1.4.3 allows a c ...

EPSS

Процентиль: 58%
0.00362
Низкий

8.1 High

CVSS3

Дефекты

CWE-284