CVE-2021-41805 log
| Source |
|
| Severity | Medium |
| Remote | Yes |
| Type | Privilege escalation |
| Description | A vulnerability was identified in Consul Enterprise before version 1.10.4 such that an ACL token with the default operator:write permissions in one namespace may be used to escalate privileges into any other permissions across all namespaces. |
| Group | Package | Affected | Fixed | Severity | Status | Ticket |
|---|---|---|---|---|---|---|
| AVG-2594 | consul | 1.10.3-1 | Medium | Not affected |
| References |
|---|
https://discuss.hashicorp.com/t/hcsec-2021-29-consul-enterprise-namespace-default-acls-allow-privilege-escalation/31871 |