vulnerability

FreeBSD: VID-8d17229f-3054-11eb-a455-ac1f6b16e566 (CVE-2020-28053): consul -- Fix Consul Connect CA private key configuration

Severity
4
CVSS
(AV:N/AC:L/Au:S/C:P/I:N/A:N)
Published
Dec 6, 2020
Added
Dec 7, 2020
Modified
Dec 10, 2025

Description

Hashicorp reports: Increase the permissions to read from the /connect/ca/configuration endpoint to operator:write. Previously Connect CA configuration, including the private key, set via this endpoint could be read back by an operator with operator:read privileges.

Solution

freebsd-upgrade-package-consul
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.