CVE Vulnerabilities

CVE-2020-12797

Published: Jun 11, 2020 | Modified: Jul 21, 2021
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

HashiCorp Consul and Consul Enterprise failed to enforce changes to legacy ACL token rules due to non-propagation to secondary data centers. Introduced in 1.4.0, fixed in 1.6.6 and 1.7.4.

Affected Software

Name Vendor Start Version End Version
Consul Hashicorp 1.4.0 (including) 1.6.6 (excluding)
Consul Hashicorp 1.4.0 (including) 1.6.6 (including)
Consul Hashicorp 1.7.0 (including) 1.7.4 (excluding)
Consul Ubuntu esm-apps/focal *
Consul Ubuntu focal *
Consul Ubuntu trusty *
Consul Ubuntu upstream *

References