HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1...
High severity
Unreviewed
Published
Dec 13, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Dec 12, 2021
Published to the GitHub Advisory Database
Dec 13, 2021
Last updated
Feb 1, 2023
HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default operator:write permissions) in one namespace can be used for unintended privilege escalation in a different namespace.
References