CVE-2021-41805 - log back

CVE-2021-41805 edited at 30 Nov 2021 20:07:27
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Privilege escalation
Description
+ A vulnerability was identified in Consul Enterprise before version 1.10.4 such that an ACL token with the default operator:write permissions in one namespace may be used to escalate privileges into any other permissions across all namespaces.
References
+ https://discuss.hashicorp.com/t/hcsec-2021-29-consul-enterprise-namespace-default-acls-allow-privilege-escalation/31871
Notes
CVE-2021-41805 created at 30 Nov 2021 20:06:30