CVE-2021-41805
high · 8.8HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default operator:write permissions) in one namespace can be used for unintended privilege escalation in a different namespace.
8.8
CVSS
34.8%
EPSS (exploit prob.)
98th
EPSS percentile
2021-12-12
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-863
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| hashicorp | consul | >= 1.7.0, < 1.8.17 |
| hashicorp | consul | >= 1.9.0, < 1.9.11 |
| hashicorp | consul | >= 1.10.0, < 1.10.4 |
Check a specific version with /api/v1/cve/match.
References
- https://discuss.hashicorp.com/t/hcsec-2021-29-consul-enterprise-namespace-default-acls-allow-privilege-escalation/31871
- https://security.netapp.com/advisory/ntap-20211229-0007/
- https://www.hashicorp.com/blog/category/consul
- https://discuss.hashicorp.com/t/hcsec-2021-29-consul-enterprise-namespace-default-acls-allow-privilege-escalation/31871
- https://security.netapp.com/advisory/ntap-20211229-0007/
- https://www.hashicorp.com/blog/category/consul
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-41805