CVE-2020-13170Improper Input Validation in Hashicorp Consul

Severity
7.5HIGHNVD
EPSS
0.5%
top 33.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateAug 21

Description

HashiCorp Consul and Consul Enterprise did not appropriately enforce scope for local tokens issued by a primary data center, where replication to a secondary data center was not enabled. Introduced in 1.4.0, fixed in 1.6.6 and 1.7.4.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDhashicorp/consul1.4.01.6.6+1
Gogithub.com/hashicorp_consul1.6.0-beta11.6.6+1
Debianhashicorp/consul< 1.7.4+dfsg1-1
debiandebian/consul< consul 1.7.4+dfsg1-1 (bullseye)

Patches

🔴Vulnerability Details

4
OSV
Improper Input Validation in HashiCorp Consul in github.com/hashicorp/consul2024-08-21
GHSA
Improper Input Validation in HashiCorp Consul2021-05-18
OSV
Improper Input Validation in HashiCorp Consul2021-05-18
OSV
CVE-2020-13170: HashiCorp Consul and Consul Enterprise did not appropriately enforce scope for local tokens issued by a primary data center, where replication to a se2020-06-11

📋Vendor Advisories

1
Debian
CVE-2020-13170: consul - HashiCorp Consul and Consul Enterprise did not appropriately enforce scope for l...2020