
Cloud Vulnerability DB
A community-led vulnerabilities database
HashiCorp Consul and Consul Enterprise experienced a security vulnerability (CVE-2020-12797) where changes to legacy ACL token rules failed to propagate to secondary data centers. This vulnerability was introduced in version 1.4.0 and was fixed in versions 1.6.6 and 1.7.4, released on June 10, 2020 (HashiCorp Changelog).
The vulnerability occurred in multi-datacenter Consul deployments where one datacenter acts as primary and others as secondary. When using legacy APIs to create or update legacy ACLs, an internal conversion process failed to compute a necessary field. As a result, when replicating legacy token updates, changes to a legacy ACL token's rules would not be propagated to secondary datacenters, potentially leaving them with outdated permissions (GitHub PR).
This vulnerability could lead to inconsistent access control enforcement across datacenters. If a token's permissions were reduced in the primary datacenter, the secondary datacenter might continue to allow access with the old permissions, potentially allowing unauthorized access to resources (GitHub PR).
The vulnerability affects environments using Consul in a multi-datacenter setup with legacy ACL tokens. It specifically impacts scenarios where token replication is enabled between primary and secondary datacenters, and where legacy ACL tokens are being modified (GitHub PR).
The primary mitigation is to upgrade to Consul version 1.7.4 or 1.6.6. Alternative mitigations include either disabling token replication in secondary datacenters (which forces all token resolution against the primary DC), or deleting and recreating tokens instead of updating them in the primary datacenter (GitHub PR).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."