CVE-2021-41805: High severity hashicorp consul vulnerability
HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default operator:write permissions) in one namespace can be used for unintended privilege escalation in a different namespace.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-41805?
The severity of CVE-2021-41805 is high with a CVSS score of 8.8.
What is the vulnerability in HashiCorp Consul Enterprise?
The vulnerability in HashiCorp Consul Enterprise is Incorrect Access Control.
How can an ACL token be used for privilege escalation in HashiCorp Consul Enterprise?
An ACL token (with the default operator:write permissions) in one namespace can be used for unintended privilege escalation in a different namespace.
Which versions of HashiCorp Consul Enterprise are affected by CVE-2021-41805?
HashiCorp Consul Enterprise versions before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 are affected by CVE-2021-41805.
How can I fix the Incorrect Access Control vulnerability in HashiCorp Consul Enterprise?
To fix the Incorrect Access Control vulnerability in HashiCorp Consul Enterprise, update to version 1.8.17, 1.9.11, or 1.10.4.