CWE
476
Advisory Published
Advisory Published
Updated

CVE-2023-0845: Consul Server Panic when Ingress and API Gateways Configured with Peering

First published: Thu Mar 09 2023(Updated: )

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) an authenticated user with service:write permissions could trigger a workflow that causes Consul server and client agents to crash under certain circumstances. To exploit this vulnerability, an attacker requires access to an ACL token with service:write permissions, and there needs to be at least one running ingress or API gateway that is configured to route traffic to an upstream service.

Credit: security@hashicorp.com security@hashicorp.com security@hashicorp.com

Affected SoftwareAffected VersionHow to fix
HashiCorp Consul<1.14.5
go/github.com/hashicorp/consul>=1.14.0<1.14.5
1.14.5

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2023-0845?

    CVE-2023-0845 is a vulnerability found in Consul and Consul Enterprise that allows an authenticated user with service:write permissions to trigger a workflow that causes Consul server and client agents to crash.

  • How does CVE-2023-0845 impact Consul and Consul Enterprise?

    CVE-2023-0845 can crash Consul server and client agents when an authenticated user with service:write permissions triggers a certain workflow.

  • What is the severity of CVE-2023-0845?

    The severity of CVE-2023-0845 is rated as medium, with a CVSS score of 6.5.

  • Which versions of Consul and Consul Enterprise are affected by CVE-2023-0845?

    Versions up to and including 1.14.5 of Consul and versions between 1.14.0 and 1.14.5 of the go package github.com/hashicorp/consul are affected by CVE-2023-0845.

  • How can CVE-2023-0845 be fixed?

    To fix CVE-2023-0845, users should upgrade to a version of Consul and the go package github.com/hashicorp/consul that is higher than 1.14.5.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203