Description
HashiCorp Consul and Consul Enterprise 1.2.0 up to 1.8.5 allowed operators with operator:read ACL permissions to read the Connect CA private key configuration. Fixed in 1.6.10, 1.7.10, and 1.8.6.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0275 | HashiCorp Consul and Consul Enterprise 1.2.0 up to 1.8.5 allowed operators with operator:read ACL permissions to read the Connect CA private key configuration. Fixed in 1.6.10, 1.7.10, and 1.8.6. |
Github GHSA |
GHSA-6m72-467w-94rh | Privilege Escalation in HashiCorp Consul |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T16:33:56.879Z
Reserved: 2020-11-02T00:00:00.000Z
Link: CVE-2020-28053
No data.
Status : Modified
Published: 2020-11-23T14:15:12.377
Modified: 2024-11-21T05:22:17.453
Link: CVE-2020-28053
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA