CVE-2019-16377Improper Access Control in Consul

Severity
9.8CRITICALNVD
EPSS
1.3%
top 19.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 23
Latest updateNov 11

Description

The makandra consul gem through 1.0.2 for Ruby has Incorrect Access Control.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDmakandra/consul1.0.2
RubyGemshashicorp/consul< 1.0.3

🔴Vulnerability Details

2
OSV
Consul gem insufficient authentication check - Multiple powers in one controller are not always checked correctly2019-09-27
GHSA
Consul gem insufficient authentication check - Multiple powers in one controller are not always checked correctly2019-09-27

💬Community

3
Bugzilla
CVE-2019-16377 consul: unauthenticated access to certain controller actions2019-11-11
Bugzilla
CVE-2019-16377 consul: unauthenticated access to certain controller actions [fedora-all]2019-11-11
Bugzilla
CVE-2019-16377 consul: unauthenticated access to certain controller actions [epel-6]2019-11-11