A vulnerability was identified in Consul Enterprise before version 1.10.4 such that an ACL token with the default operator:write permissions in one namespace may be used to escalate privileges into any other permissions across all namespaces.
A vulnerability was identified in Consul Enterprise before version 1.10.4 such that an ACL token with the default operator:write permissions in one namespace may be used to escalate privileges into any other permissions across all namespaces.
https://discuss.hashicorp.com/t/hcsec-2021-29-consul-enterprise-namespace-default-acls-allow-privilege-escalation/31871