PT-2019-18973 · Hashicorp+1 · Hashicorp Consul+2
Mkeeler
·
Publicado
2019-03-05
·
Atualizado
2024-08-20
·
CVE-2019-8336
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
HashiCorp Consul (and Consul Enterprise) versions 1.4.0 through 1.4.2
Description
The issue allows a client to bypass intended access restrictions and obtain the privileges of one other arbitrary token within secondary datacenters. This occurs because a token with literally "" as its secret is used in unusual circumstances.
Recommendations
For HashiCorp Consul (and Consul Enterprise) versions 1.4.0 through 1.4.2, update to version 1.4.3 or later to resolve the issue.
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Hashicorp Consul Enterprise
Hashicorp Consul