CVE-2021-41805 log
Source |
|
Severity | Medium |
Remote | Yes |
Type | Privilege escalation |
Description | A vulnerability was identified in Consul Enterprise before version 1.10.4 such that an ACL token with the default operator:write permissions in one namespace may be used to escalate privileges into any other permissions across all namespaces. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-2594 | consul | 1.10.3-1 | Medium | Not affected |
References |
---|
https://discuss.hashicorp.com/t/hcsec-2021-29-consul-enterprise-namespace-default-acls-allow-privilege-escalation/31871 |