VYPR
High severity8.1OSV Advisory· Published Mar 5, 2019· Updated Jun 17, 2026

CVE-2019-8336

CVE-2019-8336

Description

HashiCorp Consul (and Consul Enterprise) 1.4.x before 1.4.3 allows a client to bypass intended access restrictions and obtain the privileges of one other arbitrary token within secondary datacenters, because a token with literally "" as its secret is used in unusual circumstances.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/hashicorp/consulGo
>= 1.4.0, < 1.4.31.4.3

Affected products

4
  • Hashicorp/ConsulOSV3 versions
    v1.4.0, v1.4.1, v1.4.2+ 2 more
    • (no CPE)range: v1.4.0, v1.4.1, v1.4.2
    • cpe:2.3:a:hashicorp:consul:*:*:*:*:community:*:*:*range: >=1.4.0,<1.4.3
    • cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*range: >=1.4.0,<1.4.3
  • ghsa-coords
    Range: >= 1.4.0, < 1.4.3

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.