Improper Input Validation in HashiCorp Consul
Moderate severity
GitHub Reviewed
Published
May 18, 2021
to the GitHub Advisory Database
•
Updated Oct 2, 2023
Package
Affected versions
>= 1.6.0-beta1, < 1.6.6
>= 1.7.0, < 1.7.4
Patched versions
1.6.6
1.7.4
Description
Reviewed
May 12, 2021
Published to the GitHub Advisory Database
May 18, 2021
Last updated
Oct 2, 2023
HashiCorp Consul and Consul Enterprise did not appropriately enforce scope for local tokens issued by a primary data center, where replication to a secondary data center was not enabled. Introduced in 1.4.0, fixed in 1.6.6 and 1.7.4.
Specific Go Packages Affected
github.com/hashicorp/consul/agent
References