Vulnerability Description
HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resulting in potential unintended information disclosure. Fixed in 1.6.3.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hashicorp | Consul | >= 1.4.1, < 1.6.2 |
Related Weaknesses (CWE)
References
- https://github.com/hashicorp/consul/issues/7160Third Party Advisory
- https://www.hashicorp.com/blog/category/consul/Vendor Advisory
- https://github.com/hashicorp/consul/issues/7160Third Party Advisory
- https://www.hashicorp.com/blog/category/consul/Vendor Advisory
FAQ
What is CVE-2020-7955?
CVE-2020-7955 is a vulnerability with a CVSS score of 5.3 (MEDIUM). HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resulting in potential unintended information disclosure. Fixed in 1.6.3.
How severe is CVE-2020-7955?
CVE-2020-7955 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-7955?
Check the references section above for vendor advisories and patch information. Affected products include: Hashicorp Consul.