Vulnerabilities > CVE-2019-8336 - Unspecified vulnerability in Hashicorp Consul 1.4.0/1.4.1/1.4.2

047910
CVSS 8.1 - HIGH
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
high complexity
hashicorp

Summary

HashiCorp Consul (and Consul Enterprise) 1.4.x before 1.4.3 allows a client to bypass intended access restrictions and obtain the privileges of one other arbitrary token within secondary datacenters, because a token with literally "<hidden>" as its secret is used in unusual circumstances.

Vulnerable Configurations

Part Description Count
Application
Hashicorp
8