PT-2019-18973 · Hashicorp+1 · Hashicorp Consul+2

Mkeeler

·

Publicado

2019-03-05

·

Atualizado

2024-08-20

·

CVE-2019-8336

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HashiCorp Consul (and Consul Enterprise) versions 1.4.0 through 1.4.2
Description The issue allows a client to bypass intended access restrictions and obtain the privileges of one other arbitrary token within secondary datacenters. This occurs because a token with literally "" as its secret is used in unusual circumstances.
Recommendations For HashiCorp Consul (and Consul Enterprise) versions 1.4.0 through 1.4.2, update to version 1.4.3 or later to resolve the issue.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-1446
CVE-2019-8336
GHSA-FHM8-CXCV-PWVC
GO-2023-1945

Produtos afetados

Alt Linux
Hashicorp Consul Enterprise
Hashicorp Consul