CVE-2020-7955

MEDIUM

HashiCorp Consul <1.6.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resulting in potential unintended information disclosure. Fixed in 1.6.3.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://www.hashicorp.com/blog/category/consul/
Third Party Advisory x_refsource_misc
https://github.com/hashicorp/consul/issues/7160

Scores

CVSS v3 5.3
EPSS 0.0033
EPSS Percentile 56.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-863
Status published
Products (2)
hashicorp/consul 1.4.1 - 1.6.2 (2 CPE variants)
hashicorp/consul 1.4.1 - 1.6.3Go
Published Jan 31, 2020
Tracked Since Feb 18, 2026