CVE-2020-28053

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/11/2020
Last modified:
25/10/2022

Description

HashiCorp Consul and Consul Enterprise 1.2.0 up to 1.8.5 allowed operators with operator:read ACL permissions to read the Connect CA private key configuration. Fixed in 1.6.10, 1.7.10, and 1.8.6.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:* 1.2.0 (including) 1.6.10 (excluding)
cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:* 1.2.0 (including) 1.6.10 (excluding)
cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:* 1.7.0 (including) 1.7.10 (excluding)
cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:* 1.7.0 (including) 1.7.10 (excluding)
cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:* 1.8.0 (including) 1.8.6 (excluding)
cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:* 1.8.0 (including) 1.8.6 (excluding)