#VU21292 Improper access control in consul - CVE-2019-16377
Published: September 24, 2019 / Updated: September 24, 2019
consul
makandra
Description
The vulnerability allows a remote attacker to gain unauthorized access to certain controller actions.
The vulnerability exists in the consul gem for Ruby on Rails when processing multiple power directives. As a result, the ":only" and ":except" options of the last directive apply to all previous directives. A remote attacker can gain unauthenticated access to certain controller actions.