Vulnerability CVE-2020-13170: Information

Description

HashiCorp Consul and Consul Enterprise did not appropriately enforce scope for local tokens issued by a primary data center, where replication to a secondary data center was not enabled. Introduced in 1.4.0, fixed in 1.6.6 and 1.7.4.

Severity: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Published: June 11, 2020
Modified: June 17, 2020
Error type identifier: CWE-20

Fixed packages

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*
      Start including
      1.7.0
      End excliding
      1.7.4

      cpe:2.3:a:hashicorp:consul:*:*:*:*:*:*:*:*
      Start including
      1.7.0
      End excliding
      1.7.4

      cpe:2.3:a:hashicorp:consul:*:*:*:*:*:*:*:*
      Start including
      1.4.0
      End excliding
      1.6.6

      cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*
      Start including
      1.4.0
      End excliding
      1.6.6