Incorrect Permission Assignment for Critical Resource in Hashicorp Consul
Moderate severity
GitHub Reviewed
Published
Jun 23, 2021
to the GitHub Advisory Database
•
Updated Oct 2, 2023
Package
Affected versions
>= 1.6.0, < 1.6.6
>= 1.7.0, < 1.7.4
Patched versions
1.6.6
1.7.4
Description
Published by the National Vulnerability Database
Jun 11, 2020
Reviewed
May 12, 2021
Published to the GitHub Advisory Database
Jun 23, 2021
Last updated
Oct 2, 2023
HashiCorp Consul and Consul Enterprise failed to enforce changes to legacy ACL token rules due to non-propagation to secondary data centers. Introduced in 1.4.0, fixed in 1.6.6 and 1.7.4.
Specific Go Packages Affected
github.com/hashicorp/consul/agent/structs
References