Описание
HashiCorp Consul 1.4.0 through 1.5.0 has Incorrect Access Control. Keys not matching a specific ACL rule used for prefix matching in a policy can be deleted by a token using that policy even with default deny settings configured.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support, was needs-triage |
| devel | DNE | |
| esm-apps/bionic | needs-triage | |
| esm-apps/focal | not-affected | 1.5.2+dfsg2-14 |
| esm-apps/jammy | not-affected | |
| esm-infra-legacy/trusty | DNE | |
| focal | not-affected | 1.5.2+dfsg2-14 |
| groovy | not-affected | |
| hirsute | not-affected | |
| impish | not-affected |
Показывать по
EPSS
6.4 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
HashiCorp Consul 1.4.0 through 1.5.0 has Incorrect Access Control. Keys not matching a specific ACL rule used for prefix matching in a policy can be deleted by a token using that policy even with default deny settings configured.
HashiCorp Consul 1.4.0 through 1.5.0 has Incorrect Access Control. Key ...
HashiCorp Consul Incorrect Access Control vulnerability
EPSS
6.4 Medium
CVSS2
7.5 High
CVSS3