Lucene search

K
osvGoogleOSV:GHSA-FHM8-CXCV-PWVC
HistoryMay 13, 2022 - 1:22 a.m.

HashiCorp Consul Access Restriction Bypass

2022-05-1301:22:55
Google
osv.dev
6

6.9 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

59.9%

HashiCorp Consul (and Consul Enterprise) 1.4.x before 1.4.3 allows a client to bypass intended access restrictions and obtain the privileges of one other arbitrary token within secondary datacenters, because a token with literally “<hidden>” as its secret is used in unusual circumstances.

6.9 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

59.9%