Vulnerabilities > CVE-2019-8336 - Unspecified vulnerability in Hashicorp Consul 1.4.0/1.4.1/1.4.2

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
hashicorp

Summary

HashiCorp Consul (and Consul Enterprise) 1.4.x before 1.4.3 allows a client to bypass intended access restrictions and obtain the privileges of one other arbitrary token within secondary datacenters, because a token with literally "<hidden>" as its secret is used in unusual circumstances.

Vulnerable Configurations

Part Description Count
Application
Hashicorp
8