CVE-2019-12291: High severity hashicorp consul vulnerability
HashiCorp Consul 1.4.0 through 1.5.0 has Incorrect Access Control. Keys not matching a specific ACL rule used for prefix matching in a policy can be deleted by a token using that policy even with default deny settings configured.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-12291?
CVE-2019-12291 is a vulnerability in HashiCorp Consul 1.4.0 through 1.5.0 that allows a token to delete keys that do not match a specific ACL rule.
How severe is CVE-2019-12291?
CVE-2019-12291 has a severity rating of 7.5, which is considered high.
Which software versions are affected by CVE-2019-12291?
HashiCorp Consul versions 1.4.0 through 1.5.0 are affected by CVE-2019-12291.
How can I fix CVE-2019-12291?
To fix CVE-2019-12291, upgrade to version 1.5.1 of HashiCorp Consul.
Where can I find more information about CVE-2019-12291?
You can find more information about CVE-2019-12291 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-12291), [GitHub Issue](https://github.com/hashicorp/consul/issues/5888), [GitHub Commit](https://github.com/hashicorp/consul/commit/36ebca1fd0129278487c6570449bc8cc03987890).