CVE Vulnerabilities

CVE-2023-1297

Published: Jun 02, 2023 | Modified: Jun 12, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Consul and Consul Enterprises cluster peering implementation contained a flaw whereby a peer cluster with service of the same name as a local service could corrupt Consul state, resulting in denial of service. This vulnerability was resolved in Consul 1.14.5, and 1.15.3

Affected Software

Name Vendor Start Version End Version
Consul Hashicorp 1.13.0 (including) 1.14.7 (excluding)
Consul Hashicorp 1.15.0 (including) 1.15.3 (excluding)

References