PT-2023-2223 · Hashicorp+2 · Hashicorp Consul+3

Published

2023-03-07

·

Updated

2024-08-20

·

CVE-2023-0845

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Consul versions prior to 1.14.5 Consul Enterprise versions prior to 1.14.5
Description The issue is related to an authenticated user with service:write permissions triggering a workflow that causes the Consul server and client agents to crash under certain circumstances. To exploit this, an attacker requires access to an ACL token with service:write permissions and at least one running ingress or API gateway configured to route traffic to an upstream service. The vulnerability is also associated with pointer dereference errors.
Recommendations For Consul versions prior to 1.14.5, update to Consul 1.14.5 to resolve the issue. For Consul Enterprise versions prior to 1.14.5, update to Consul Enterprise 1.14.5 to resolve the issue. As a temporary workaround, consider restricting access to service:write permissions to minimize the risk of exploitation. Restrict access to ingress or API gateways that are configured to route traffic to an upstream service until the issue is resolved.

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1696
ALT-PU-2023-7106
ALT-PU-2024-8028
BDU:2023-01973
BIT-CONSUL-2023-0845
CVE-2023-0845
GHSA-WJ6X-HCC2-F32J
GO-2023-1639

Affected Products

Alt Linux
Hashicorp Consul
Hashicorp Consul Enterprise
Red Os