CVE-2019-8336: Permissions, Privileges, and Access Controls
(updated )
HashiCorp Consul (and Consul Enterprise) allows a client to bypass intended access restrictions and obtain the privileges of one other arbitrary token within secondary datacenters, because a token with literally <hidden>
as its secret is used in unusual circumstances.
References
Detect and mitigate CVE-2019-8336 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →