PT-2019-12736 · Hashicorp+1 · Hashicorp Consul+1

Danlsgiga

·

Published

2019-06-06

·

Updated

2024-08-20

·

CVE-2019-12291

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions HashiCorp Consul versions 1.4.0 through 1.5.0
Description The issue is related to Incorrect Access Control in HashiCorp Consul. Keys not matching a specific ACL rule used for prefix matching in a policy can be deleted by a token using that policy, even with default deny settings configured. This affects the github.com/hashicorp/consul and github.com/hashicorp/consul/acl packages.
Recommendations For HashiCorp Consul versions 1.4.0 through 1.5.0, consider restricting access to the ACL rules used for prefix matching in policies to minimize the risk of unauthorized key deletion. As a temporary workaround, review and adjust the default deny settings and policy configurations to ensure proper access control. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3391
ALT-PU-2020-3421
ALT-PU-2022-1256
CVE-2019-12291
GHSA-H65H-V7FW-4P38
GO-2023-1852

Affected Products

Alt Linux
Hashicorp Consul