VDB
Sign up
HIGH8.8

GHSA-ccw8-7688-vqx4

HashiCorp Consul Privilege Escalation Vulnerability

Quick fix

GHSA-ccw8-7688-vqx4 — github.com/hashicorp/consul: upgrade to the fixed version with the command below.

go get github.com/hashicorp/consul@v1.10.2

Details

HashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.8.15, 1.9.9 and 1.10.2.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/hashicorp/consul
Introduced in: 1.10.1Fixed in: 1.10.2
Fixgo get github.com/hashicorp/consul@v1.10.2
Go/github.com/hashicorp/consul
Introduced in: 1.9.0Fixed in: 1.9.9
Fixgo get github.com/hashicorp/consul@v1.9.9
Go/github.com/hashicorp/consul
Introduced in: 0Fixed in: 1.8.15
Fixgo get github.com/hashicorp/consul@v1.8.15

References