PT-2020-13371 · Hashicorp+1 · Hashicorp Consul Enterprise+2

Published

2020-06-11

·

Updated

2024-08-21

·

CVE-2020-13170

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions HashiCorp Consul and Consul Enterprise versions 1.4.0 through 1.6.5 HashiCorp Consul and Consul Enterprise versions 1.7.0 through 1.7.3
Description The issue arises from the improper enforcement of scope for local tokens issued by a primary data center when replication to a secondary data center is not enabled. This affects the github.com/hashicorp/consul/agent package. The problem is related to improper input validation in HashiCorp Consul.
Recommendations For HashiCorp Consul and Consul Enterprise versions 1.4.0 through 1.6.5, update to version 1.6.6 or later. For HashiCorp Consul and Consul Enterprise versions 1.7.0 through 1.7.3, update to version 1.7.4 or later. As a temporary workaround, consider restricting access to local tokens issued by the primary data center until the issue is resolved.

Fix

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3391
ALT-PU-2020-3421
ALT-PU-2022-1256
BIT-CONSUL-2020-13170
CVE-2020-13170
GHSA-P2J5-3F4C-224R
GO-2022-0859

Affected Products

Alt Linux
Hashicorp Consul Enterprise
Hashicorp Consul