CVE-2020-13170: Input Validation
HashiCorp Consul and Consul Enterprise did not appropriately enforce scope for local tokens issued by a primary data center, where replication to a secondary data center was not enabled. Introduced in 1.4.0, fixed in 1.6.6 and 1.7.4.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-13170?
CVE-2020-13170 is a vulnerability in HashiCorp Consul and Consul Enterprise that did not appropriately enforce scope for local tokens issued by a primary data center.
How severe is CVE-2020-13170?
CVE-2020-13170 has a severity rating of medium with a CVSS score of 5.3.
How do I know if I am affected by CVE-2020-13170?
If you are using HashiCorp Consul or Consul Enterprise versions between 1.6.0-beta1 and 1.6.6, or between 1.7.0 and 1.7.4, you may be affected by CVE-2020-13170.
How can I fix CVE-2020-13170?
To fix CVE-2020-13170, upgrade to version 1.6.6 or 1.7.4 of HashiCorp Consul or Consul Enterprise.
Where can I get more information about CVE-2020-13170?
You can find more information about CVE-2020-13170 on the NVD website and the official GitHub repository for HashiCorp Consul.