Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h65h-v7fw-4p38

Опубликовано: 09 июн. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

HashiCorp Consul Incorrect Access Control vulnerability

HashiCorp Consul 1.4.0 through 1.5.0 has Incorrect Access Control. Keys not matching a specific ACL rule used for prefix matching in a policy can be deleted by a token using that policy even with default deny settings configured.

Specific Go Packages Affected

github.com/hashicorp/consul/acl

Пакеты

Наименование

github.com/hashicorp/consul

go
Затронутые версииВерсия исправления

>= 1.4.0, < 1.5.1

1.5.1

EPSS

Процентиль: 61%
0.0042
Низкий

7.5 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

HashiCorp Consul 1.4.0 through 1.5.0 has Incorrect Access Control. Keys not matching a specific ACL rule used for prefix matching in a policy can be deleted by a token using that policy even with default deny settings configured.

CVSS3: 7.5
nvd
больше 6 лет назад

HashiCorp Consul 1.4.0 through 1.5.0 has Incorrect Access Control. Keys not matching a specific ACL rule used for prefix matching in a policy can be deleted by a token using that policy even with default deny settings configured.

CVSS3: 7.5
debian
больше 6 лет назад

HashiCorp Consul 1.4.0 through 1.5.0 has Incorrect Access Control. Key ...

EPSS

Процентиль: 61%
0.0042
Низкий

7.5 High

CVSS3

Дефекты

CWE-284