CVE-2023-0845: Consul Server Panic when Ingress and API Gateways Configured with Peering
A vulnerability was identified in Consul and Consul Enterprise (“Consul”) an authenticated user with service:write permissions could trigger a workflow that causes Consul server and client agents to crash under certain circumstances. To exploit this vulnerability, an attacker requires access to an ACL token with service:write permissions, and there needs to be at least one running ingress or API gateway that is configured to route traffic to an upstream service.
Other sources
Consul and Consul Enterprise allowed an authenticated user with service:write permissions to trigger a workflow that causes Consul server and client agents to crash under certain circumstances. This vulnerability was fixed in Consul 1.14.5.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-0845?
CVE-2023-0845 is a vulnerability found in Consul and Consul Enterprise that allows an authenticated user with service:write permissions to trigger a workflow that causes Consul server and client agents to crash.
How does CVE-2023-0845 impact Consul and Consul Enterprise?
CVE-2023-0845 can crash Consul server and client agents when an authenticated user with service:write permissions triggers a certain workflow.
What is the severity of CVE-2023-0845?
The severity of CVE-2023-0845 is rated as medium, with a CVSS score of 6.5.
Which versions of Consul and Consul Enterprise are affected by CVE-2023-0845?
Versions up to and including 1.14.5 of Consul and versions between 1.14.0 and 1.14.5 of the go package github.com/hashicorp/consul are affected by CVE-2023-0845.
How can CVE-2023-0845 be fixed?
To fix CVE-2023-0845, users should upgrade to a version of Consul and the go package github.com/hashicorp/consul that is higher than 1.14.5.