PT-2019-18973 · Hashicorp+1 · Hashicorp Consul+2
Mkeeler
·
Published
2019-03-05
·
Updated
2024-08-20
·
CVE-2019-8336
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
HashiCorp Consul (and Consul Enterprise) versions 1.4.0 through 1.4.2
Description
The issue allows a client to bypass intended access restrictions and obtain the privileges of one other arbitrary token within secondary datacenters. This occurs because a token with literally "" as its secret is used in unusual circumstances.
Recommendations
For HashiCorp Consul (and Consul Enterprise) versions 1.4.0 through 1.4.2, update to version 1.4.3 or later to resolve the issue.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Hashicorp Consul Enterprise
Hashicorp Consul