CVE-2019-12291
06.06.2019, 17:29
HashiCorp Consul 1.4.0 through 1.5.0 has Incorrect Access Control. Keys not matching a specific ACL rule used for prefix matching in a policy can be deleted by a token using that policy even with default deny settings configured.Enginsight
Vendor | Product | Version |
---|---|---|
hashicorp | consul | 1.4.0 ≤ 𝑥 ≤ 1.5.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases