hashicorp consul CVE-2020-28053 is a vulnerability in HashiCorp Consul
Published on November 23, 2020

HashiCorp Consul and Consul Enterprise 1.2.0 up to 1.8.5 allowed operators with operator:read ACL permissions to read the Connect CA private key configuration. Fixed in 1.6.10, 1.7.10, and 1.8.6.

Vendor Advisory NVD


Products Associated with CVE-2020-28053

Want to know whenever a new CVE is published for HashiCorp Consul? stack.watch will email you.

 

Exploit Probability

EPSS
0.26%
Percentile
48.75%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.