consul/website/pages
Freddy 4e44341d36 Require operator:write to get Connect CA config (#9240)
A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that operators with `operator:read` ACL permissions are able to read the Consul Connect CA configuration when explicitly configured with the `/v1/connect/ca/configuration` endpoint, including the private key. This allows the user to effectively privilege escalate by enabling the ability to mint certificates for any Consul Connect services. This would potentially allow them to masquerade (receive/send traffic) as any service in the mesh.

--

This PR increases the permissions required to read the Connect CA's private key when it was configured via the `/connect/ca/configuration` endpoint. They are now `operator:write`.
2020-11-19 16:50:17 -07:00
..
api-docs Require operator:write to get Connect CA config (#9240) 2020-11-19 16:50:17 -07:00
commands Add a CLI command for retrieving the autopilot configuration. (#9142) 2020-11-11 18:19:32 +00:00
community round 2 2020-09-15 12:01:47 -04:00
docs Merge pull request #9091 from scellef/correct-upgrade-guide 2020-11-19 00:55:51 +00:00
downloads website: update download callout for v1.9.0-rc1 2020-11-18 18:38:06 -05:00
home Add Using in Production Question (#8718) 2020-09-21 20:08:44 -04:00
intro [docs] Change links to the DNS information to the right place (#8675) 2020-11-17 15:03:27 +00:00
partials update deps, format all files 2020-07-08 19:12:34 -04:00
security remove 'sidebar_current' from frontmatter 2020-04-28 12:53:24 -04:00
use-cases Add files via upload 2020-10-13 15:16:34 -07:00
404.jsx update dependencies 2020-05-21 14:50:45 -04:00
_app.js [Website] Add HashiStackMenu to website (#8854) 2020-10-09 10:48:21 -05:00
_document.js
_error.jsx update dependencies 2020-05-21 14:50:45 -04:00
_temporary_button.css misc cleanup & fixes 2020-04-28 12:53:26 -04:00
index.jsx Test Netlify build 2020-05-13 23:44:22 -07:00
print.css
style.css Expose `expirationDate` prop in <AlertBanner/> 2020-10-23 11:19:41 -04:00