CVE-2020-28053: Hashicorp Consul

Medium severity, CVSS 6.5. EPSS: 1.5% chance of exploitation in the next 30 days.

HashiCorp Consul and Consul Enterprise 1.2.0 up to 1.8.5 allowed operators with operator:read ACL permissions to read the Connect CA private key configuration. Fixed in 1.6.10, 1.7.10, and 1.8.6.

Affected products

  • Hashicorp Consul: from 1.2.0, before 1.6.10 (fixed in 1.6.10); from 1.7.0, before 1.7.10 (fixed in 1.7.10); from 1.8.0, before 1.8.6 (fixed in 1.8.6)

Published 2020-11-23. Last modified 2026-06-17.