Impact
The vulnerability allows a privileged attacker who has `operator:write` permission to instruct Consul to read credential files located outside the intended scope. If succeeded, the attacker can receive these files, effectively exfiltrating sensitive secrets from the Consul server host. The flaw is caused by the Vault Connect CA provider when configured with JWT or AppRole authentication and is classified as a missing authorization weakness. The impact is the compromise of confidentiality and potential exposure of confidential data.
Affected Systems
HashiCorp Consul Community Edition and Consul Enterprise versions 1.18.21 through 2.0.2 are affected. The defect is resolved in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Risk and Exploitability
The CVSS score of 6.8 denotes a medium severity risk. No EPSS score is available, and the vulnerability is not listed in CISA's KEV catalog. The attack requires an attacker who already possesses operator:write authority, which is typically granted to trusted administrators or privileged processes. An attacker with this privilege could exploit the flaw internally or via compromised credentials to read arbitrary files and transmit them back to the attacker. The exploitation path therefore relies on inadequate authorization controls rather than remote code execution.
OpenCVE Enrichment