First published: Fri Jan 31 2020(Updated: )
HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resulting in potential unintended information disclosure. Fixed in 1.6.3.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Consul | >=1.4.1<1.6.2 | |
HashiCorp Consul | >=1.4.1<1.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-7955.
The severity rating is 5.3, which is considered medium.
The affected software is HashiCorp Consul and Consul Enterprise versions 1.4.1 through 1.6.2.
The vulnerability could result in potential unintended information disclosure.
The vulnerability is fixed in version 1.6.3 of HashiCorp Consul and Consul Enterprise.