PT-2019-12736 · Hashicorp+1 · Hashicorp Consul+1

Danlsgiga

·

Publicado

2019-06-06

·

Atualizado

2024-08-20

·

CVE-2019-12291

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions HashiCorp Consul versions 1.4.0 through 1.5.0
Description The issue is related to Incorrect Access Control in HashiCorp Consul. Keys not matching a specific ACL rule used for prefix matching in a policy can be deleted by a token using that policy, even with default deny settings configured. This affects the github.com/hashicorp/consul and github.com/hashicorp/consul/acl packages.
Recommendations For HashiCorp Consul versions 1.4.0 through 1.5.0, consider restricting access to the ACL rules used for prefix matching in policies to minimize the risk of unauthorized key deletion. As a temporary workaround, review and adjust the default deny settings and policy configurations to ensure proper access control. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2020-3391
ALT-PU-2020-3421
ALT-PU-2022-1256
CVE-2019-12291
GHSA-H65H-V7FW-4P38
GO-2023-1852

Produtos afetados

Alt Linux
Hashicorp Consul