CVE-2021-41805
HashiCorp Consul Enterprise Privilege Escalation / Remote Code Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default operator:write permissions) in one namespace can be used for unintended privilege escalation in a different namespace.
HashiCorp Consul Enterprise versiones anteriores a 1.8.17, 1.9.x anteriores a 1.9.11 y 1.10.x anteriores a 1.10.4, presenta un Control de Acceso Incorrecto. Un token ACL (con el operador predeterminado: permisos de escritura) en un espacio de nombres puede ser usado para una escalada de privilegios no intencionada en un espacio de nombres diferente
Hashicorp Consul Enterprise has an issue where an ACL token (with the default operator:write permissions) in one namespace can be used for unintended privilege escalation in a different namespace. This can be abused to gain remote code execution with escalated privileges.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-09-29 CVE Reserved
- 2021-12-12 CVE Published
- 2022-12-07 First Exploit
- 2024-08-04 CVE Updated
- 2025-04-10 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-863: Incorrect Authorization
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://security.netapp.com/advisory/ntap-20211229-0007 | Third Party Advisory |
|
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/183438 | 2025-01-09 | |
https://github.com/blackm4c/CVE-2021-41805 | 2022-12-07 | |
https://github.com/acfirthh/CVE-2021-41805 | 2025-01-07 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hashicorp Search vendor "Hashicorp" | Consul Search vendor "Hashicorp" for product "Consul" | >= 1.7.0 < 1.8.17 Search vendor "Hashicorp" for product "Consul" and version " >= 1.7.0 < 1.8.17" | enterprise |
Affected
| ||||||
Hashicorp Search vendor "Hashicorp" | Consul Search vendor "Hashicorp" for product "Consul" | >= 1.9.0 < 1.9.11 Search vendor "Hashicorp" for product "Consul" and version " >= 1.9.0 < 1.9.11" | enterprise |
Affected
| ||||||
Hashicorp Search vendor "Hashicorp" | Consul Search vendor "Hashicorp" for product "Consul" | >= 1.10.0 < 1.10.4 Search vendor "Hashicorp" for product "Consul" and version " >= 1.10.0 < 1.10.4" | enterprise |
Affected
|