PT-2019-14649 · Hashicorp · Consul Ruby Gem

Kratob

·

Publicado

2019-09-23

·

Atualizado

2020-08-24

·

CVE-2019-16377

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions consul ruby gem versions prior to 1.0.3
Description The issue is related to Incorrect Access Control in the consul ruby gem. Specifically, when a controller checks multiple powers using :if or :except conditions, these conditions are applied to all power checks in that controller, leading to skipped power checks and potentially allowing unauthenticated access to certain controller actions.
Recommendations For consul ruby gem versions prior to 1.0.3, update to version 1.0.3 or later to resolve the issue. As a temporary workaround, consider reviewing and manually validating all power checks in controllers to ensure correct access control until the update can be applied.

Exploit

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-16377
GHSA-8JHX-9GF4-HHF5

Produtos afetados

Consul Ruby Gem