VYPR
Medium severity6.5NVD Advisory· Published Nov 23, 2020· Updated Jun 17, 2026

CVE-2020-28053

CVE-2020-28053

Description

HashiCorp Consul and Consul Enterprise 1.2.0 up to 1.8.5 allowed operators with operator:read ACL permissions to read the Connect CA private key configuration. Fixed in 1.6.10, 1.7.10, and 1.8.6.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/hashicorp/consulGo
>= 1.2.0, < 1.6.101.6.10
github.com/hashicorp/consulGo
>= 1.7.0, < 1.7.101.7.10
github.com/hashicorp/consulGo
>= 1.8.0, < 1.8.61.8.6

Affected products

5
  • Hashicorp/Consul2 versions
    cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:*+ 1 more
    • cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:*range: >=1.2.0,<1.6.10
    • cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*range: >=1.2.0,<1.6.10
  • HashiCorp/Consuldescription
  • osv-coords2 versions
    >= 1.2.0, < 1.6.10+ 1 more
    • (no CPE)range: >= 1.2.0, < 1.6.10
    • (no CPE)range: >= 1.2.0, < 1.6.10

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.