Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-7955

Опубликовано: 29 янв. 2020
Источник: redhat
CVSS3: 5.3

Описание

HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resulting in potential unintended information disclosure. Fixed in 1.6.3.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 1servicemeshNot affected
OpenShift Service Mesh 1servicemesh-operatorNot affected
OpenShift Service Mesh 1servicemesh-prometheusNot affected
Red Hat Fuse 7consul-clientNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-841
https://bugzilla.redhat.com/show_bug.cgi?id=1805875consul: Missing access control in HTTP API endpoints

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 6 лет назад

HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resulting in potential unintended information disclosure. Fixed in 1.6.3.

CVSS3: 5.3
nvd
больше 6 лет назад

HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resulting in potential unintended information disclosure. Fixed in 1.6.3.

CVSS3: 5.3
debian
больше 6 лет назад

HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uni ...

CVSS3: 5.3
github
около 5 лет назад

Incorrect Authorization in HashiCorp Consul

5.3 Medium

CVSS3