HashiCorp Consul (and Consul Enterprise) 1.4.x before 1.4.3 allows a client to bypass intended access restrictions and obtain the privileges of one other arbitrary token within secondary datacenters, because a token with literally "" as its secret is used in unusual circumstances.
{
"cpe": [
"cpe:2.3:a:hashicorp:consul:*:*:*:*:community:*:*:*",
"cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*"
],
"extracted_events": [
{
"introduced": "1.4.0"
},
{
"fixed": "1.4.3"
}
],
"source": "CPE_RANGE"
}