PT-2023-9290 · Hashicorp+2 · Hashicorp Consul Enterprise+3

CVE-2023-1297

·

Publicado

2023-06-02

·

Atualizado

2024-08-20

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Consul versions prior to 1.14.5 Consul versions prior to 1.15.3 Consul Enterprise versions prior to 1.14.5 Consul Enterprise versions prior to 1.15.3
Description The cluster peering implementation in Consul and Consul Enterprise contained a flaw that could allow a peer cluster with a service of the same name as a local service to corrupt Consul state, resulting in denial of service.
Recommendations For Consul versions prior to 1.14.5, update to version 1.14.5 or later to resolve the issue. For Consul versions prior to 1.15.3, update to version 1.15.3 or later to resolve the issue. For Consul Enterprise versions prior to 1.14.5, update to version 1.14.5 or later to resolve the issue. For Consul Enterprise versions prior to 1.15.3, update to version 1.15.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the cluster peering implementation until a patch is available.

Exploit

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-1946
BDU:2024-06032
BIT-CONSUL-2023-1297
CVE-2023-1297
GHSA-C57C-7HRJ-6Q6V
GO-2023-1827

Produtos afetados

Alt Linux
Hashicorp Consul
Hashicorp Consul Enterprise
Red Os