First published: Sun Dec 12 2021(Updated: )
HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default operator:write permissions) in one namespace can be used for unintended privilege escalation in a different namespace.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Consul | >=1.7.0<1.8.17 | |
HashiCorp Consul | >=1.9.0<1.9.11 | |
HashiCorp Consul | >=1.10.0<1.10.4 | |
>=1.7.0<1.8.17 | ||
>=1.9.0<1.9.11 | ||
>=1.10.0<1.10.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-41805 is high with a CVSS score of 8.8.
The vulnerability in HashiCorp Consul Enterprise is Incorrect Access Control.
An ACL token (with the default operator:write permissions) in one namespace can be used for unintended privilege escalation in a different namespace.
HashiCorp Consul Enterprise versions before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 are affected by CVE-2021-41805.
To fix the Incorrect Access Control vulnerability in HashiCorp Consul Enterprise, update to version 1.8.17, 1.9.11, or 1.10.4.