QID 981946
QID 981946: Go (go) Security Update for github.com/hashicorp/consul (GHSA-r9w6-rhh9-7v53)
HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resulting in potential unintended information disclosure. Fixed in 1.6.3.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-r9w6-rhh9-7v53 for updates pertaining to this vulnerability.
Vendor References
- GHSA-r9w6-rhh9-7v53 -
github.com/advisories/GHSA-r9w6-rhh9-7v53
CVEs related to QID 981946
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-r9w6-rhh9-7v53 | github.com/hashicorp/consul |
|