PT-2023-9290 · Hashicorp+2 · Hashicorp Consul+3

Published

2023-06-02

·

Updated

2024-08-20

·

CVE-2023-1297

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Consul versions prior to 1.14.5 Consul versions prior to 1.15.3 Consul Enterprise versions prior to 1.14.5 Consul Enterprise versions prior to 1.15.3
Description The cluster peering implementation in Consul and Consul Enterprise contained a flaw that could allow a peer cluster with a service of the same name as a local service to corrupt Consul state, resulting in denial of service.
Recommendations For Consul versions prior to 1.14.5, update to version 1.14.5 or later to resolve the issue. For Consul versions prior to 1.15.3, update to version 1.15.3 or later to resolve the issue. For Consul Enterprise versions prior to 1.14.5, update to version 1.14.5 or later to resolve the issue. For Consul Enterprise versions prior to 1.15.3, update to version 1.15.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the cluster peering implementation until a patch is available.

Fix

DoS

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1946
BDU:2024-06032
BIT-CONSUL-2023-1297
CVE-2023-1297
GHSA-C57C-7HRJ-6Q6V
GO-2023-1827

Affected Products

Alt Linux
Hashicorp Consul
Hashicorp Consul Enterprise
Red Os