CVE-2020-12797Incorrect Permission Assignment in Hashicorp Consul

Severity
5.3MEDIUMNVD
EPSS
0.4%
top 38.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateAug 21

Description

HashiCorp Consul and Consul Enterprise failed to enforce changes to legacy ACL token rules due to non-propagation to secondary data centers. Introduced in 1.4.0, fixed in 1.6.6 and 1.7.4.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

NVDhashicorp/consul1.4.01.6.6+2
Gogithub.com/hashicorp_consul1.6.01.6.6+1
Debianhashicorp/consul< 1.7.4+dfsg1-1
debiandebian/consul< consul 1.7.4+dfsg1-1 (bullseye)

Patches

🔴Vulnerability Details

4
OSV
Incorrect Permission Assignment for Critical Resource in Hashicorp Consul in github.com/hashicorp/consul2024-08-21
OSV
Incorrect Permission Assignment for Critical Resource in Hashicorp Consul2021-06-23
GHSA
Incorrect Permission Assignment for Critical Resource in Hashicorp Consul2021-06-23
OSV
CVE-2020-12797: HashiCorp Consul and Consul Enterprise failed to enforce changes to legacy ACL token rules due to non-propagation to secondary data centers2020-06-11

📋Vendor Advisories

1
Debian
CVE-2020-12797: consul - HashiCorp Consul and Consul Enterprise failed to enforce changes to legacy ACL t...2020