CVE-2023-1297 MEDIUM

CVE-2023-1297: Consul Cluster Peering can Result in Denial of Service

Vendor Hashicorp
Product Consul
Weakness CWE-826
Published June 2, 2023
Last update January 8, 2025

CVSS base score

4.9/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

What the vulnerability does

01Description

Consul and Consul Enterprise's cluster peering implementation contained a flaw whereby a peer cluster with service of the same name as a local service could corrupt Consul state, resulting in denial of service. This vulnerability was resolved in Consul 1.14.5, and 1.15.3

Key dates

02Disclosure timeline

June 2, 2023 CVE published
January 8, 2025 Record updated