Impact
Consul Community Edition and Consul Enterprise versions 1.19.1 through 2.0.2 allow an authenticated user with network access to the RPC port to delete sessions via the transaction API without requiring the {session:write} ACL permission. This bypass enables an attacker to remove protected sessions, potentially disrupting services that rely on those sessions or facilitating lateral movement by deleting tokens that are part of existing workflows.
Affected Systems
HashiCorp Consul Community Edition and HashiCorp Consul Enterprise versions 1.19.1 through 2.0.2 are affected. Enterprise users should patch to 1.21.17, 1.22.11, or 2.0.3, while Community users should upgrade to 2.0.3.
Risk and Exploitability
The vulnerability scores a CVSS of 4.2, indicating moderate risk. Exploitation requires network access to the Consul RPC port and an authenticated session, but once accessed the attacker can delete arbitrary sessions. Although EPSS is not available and the vulnerability is not listed in CISA KEV, the impact on service continuity and potential for privilege escalation warrants prompt remediation.
OpenCVE Enrichment