HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default operator:write permissions) in one namespace can be used for unintended privilege escalation in a different namespace.
{
"source": "CPE_RANGE",
"cpe": "cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*",
"extracted_events": [
{
"introduced": "1.7.0"
},
{
"fixed": "1.8.17"
},
{
"introduced": "1.9.0"
},
{
"fixed": "1.9.11"
},
{
"introduced": "1.10.0"
},
{
"fixed": "1.10.4"
}
]
}