PT-2023-9290 · Hashicorp+2 · Hashicorp Consul Enterprise+3

CVE-2023-1297

·

Published

2023-06-02

·

Updated

2024-08-20

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Consul versions prior to 1.14.5 Consul versions prior to 1.15.3 Consul Enterprise versions prior to 1.14.5 Consul Enterprise versions prior to 1.15.3
Description The cluster peering implementation in Consul and Consul Enterprise contained a flaw that could allow a peer cluster with a service of the same name as a local service to corrupt Consul state, resulting in denial of service.
Recommendations For Consul versions prior to 1.14.5, update to version 1.14.5 or later to resolve the issue. For Consul versions prior to 1.15.3, update to version 1.15.3 or later to resolve the issue. For Consul Enterprise versions prior to 1.14.5, update to version 1.14.5 or later to resolve the issue. For Consul Enterprise versions prior to 1.15.3, update to version 1.15.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the cluster peering implementation until a patch is available.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1946
BDU:2024-06032
BIT-CONSUL-2023-1297
CVE-2023-1297
GHSA-C57C-7HRJ-6Q6V
GO-2023-1827

Affected Products

Alt Linux
Hashicorp Consul
Hashicorp Consul Enterprise
Red Os