PT-2019-18973 · Hashicorp+1 · Hashicorp Consul+2

Mkeeler

·

Published

2019-03-05

·

Updated

2024-08-20

·

CVE-2019-8336

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HashiCorp Consul (and Consul Enterprise) versions 1.4.0 through 1.4.2
Description The issue allows a client to bypass intended access restrictions and obtain the privileges of one other arbitrary token within secondary datacenters. This occurs because a token with literally "" as its secret is used in unusual circumstances.
Recommendations For HashiCorp Consul (and Consul Enterprise) versions 1.4.0 through 1.4.2, update to version 1.4.3 or later to resolve the issue.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1446
CVE-2019-8336
GHSA-FHM8-CXCV-PWVC
GO-2023-1945

Affected Products

Alt Linux
Hashicorp Consul Enterprise
Hashicorp Consul