GHSA-h65h-v7fw-4p38
Dashboard / Vulnerabilities / GHSA-h65h-v7fw-4p38
GHSA-h65h-v7fw-4p38
Summary: HashiCorp Consul Incorrect Access Control vulnerability
Details: HashiCorp Consul 1.4.0 through 1.5.0 has Incorrect Access Control. Keys not matching a specific ACL rule used for prefix matching in a policy can be deleted by a token using that policy even with default deny settings configured. ### Specific Go Packages Affected github.com/hashicorp/consul/acl
References: https://nvd.nist.gov/vuln/detail/CVE-2019-12291, https://github.com/hashicorp/consul/issues/5888, https://github.com/hashicorp/consul/commit/36ebca1fd0129278487c6570449bc8cc03987890, https://github.com/hashicorp/consul, https://www.hashicorp.com/blog/category/consul
Affected packages
Package
Name: github.com/hashicorp/consul
Purl: pkg:golang/github.com/hashicorp/consul
Affected ranges
Type: SEMVER
Events:
