Vulnerabilities > CVE-2020-28053 - Incorrect Authorization vulnerability in Hashicorp Consul
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
HashiCorp Consul and Consul Enterprise 1.2.0 up to 1.8.5 allowed operators with operator:read ACL permissions to read the Connect CA private key configuration. Fixed in 1.6.10, 1.7.10, and 1.8.6.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- https://github.com/hashicorp/consul/blob/master/CHANGELOG.md#186-november-19-2020
- https://github.com/hashicorp/consul/blob/master/CHANGELOG.md#186-november-19-2020
- https://security.gentoo.org/glsa/202208-09
- https://security.gentoo.org/glsa/202208-09
- https://www.hashicorp.com/blog/category/consul
- https://www.hashicorp.com/blog/category/consul