MEDIUM
consul: Missing access control in HTTP API endpoints
Published Jan 31, 2020
5.3
MEDIUMCVSS 3.1
EPSS 1.41%
Description
HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resulting in potential unintended information disclosure. Fixed in 1.6.3.
Affected products
No data.
No data.
OpenShift Service Mesh 1
servicemesh
Not affected
OpenShift Service Mesh 1
servicemesh-operator
Not affected
OpenShift Service Mesh 1
servicemesh-prometheus
Not affected
Red Hat Fuse 7
consul-client
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Service Mesh 1 | servicemesh | Not affected | n/a |
| OpenShift Service Mesh 1 | servicemesh-operator | Not affected | n/a |
| OpenShift Service Mesh 1 | servicemesh-prometheus | Not affected | n/a |
| Red Hat Fuse 7 | consul-client | Not affected | n/a |
github.com/hashicorp/consul
Go
Introduced 1.4.1 Fixed 1.6.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/hashicorp/consul | 1.4.1 | 1.6.3 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (7)
- https://access.redhat.com/security/cve/CVE-2020-7955 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1805875 Issue Tracking
- https://github.com/advisories/GHSA-r9w6-rhh9-7v53 Advisory
- https://github.com/hashicorp/consul/issues/7160 x_refsource_MISCThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-7955
- https://www.cve.org/CVERecord?id=CVE-2020-7955
- https://www.hashicorp.com/blog/category/consul/ x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-7955 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1805875 | Issue Tracking | |
| https://github.com/advisories/GHSA-r9w6-rhh9-7v53 | Advisory | |
| https://github.com/hashicorp/consul/issues/7160 | x_refsource_MISCThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-7955 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-7955 | ||
| https://www.hashicorp.com/blog/category/consul/ | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 31, 2020
Updated Aug 4, 2024
Reserved Jan 24, 2020
Link CVE-2020-7955
CISA Vulnrichment
GHSA-R9W6-RHH9-7V53 Updated n/a