Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Mkeeler

#31624de 53,635
8.1CVSS total
Vulnerabilidades · 1
PT-2019-18973
8.1
2019-03-05
Hashicorp · Hashicorp Consul · CVE-2019-8336
**Name of the Vulnerable Software and Affected Versions** HashiCorp Consul (and Consul Enterprise) versions 1.4.0 through 1.4.2 **Description** The issue allows a client to bypass intended access restrictions and obtain the privileges of one other arbitrary token within secondary datacenters. This occurs because a token with literally "<hidden>" as its secret is used in unusual circumstances. **Recommendations** For HashiCorp Consul (and Consul Enterprise) versions 1.4.0 through 1.4.2, update to version 1.4.3 or later to resolve the issue.