CVE-2023-1297: Consul Cluster Peering can Result in Denial of Service
Consul and Consul Enterprise's cluster peering implementation contained a flaw whereby a peer cluster with service of the same name as a local service could corrupt Consul state, resulting in denial of service. This vulnerability was resolved in Consul 1.14.5, and 1.15.3
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Consul vulnerability?
The vulnerability ID of this Consul vulnerability is CVE-2023-1297.
What is the severity of CVE-2023-1297?
The severity of CVE-2023-1297 is high with a severity value of 7.5.
What software is affected by CVE-2023-1297?
Consul and Consul Enterprise versions between 1.13.0 and 1.14.7, as well as versions between 1.15.0 and 1.15.3, are affected by CVE-2023-1297.
How can Consul users fix the CVE-2023-1297 vulnerability?
To fix the CVE-2023-1297 vulnerability, Consul users should upgrade to Consul versions 1.14.5 or 1.15.3.
Where can I find more information about the CVE-2023-1297 vulnerability?
More information about the CVE-2023-1297 vulnerability can be found at the following reference: https://discuss.hashicorp.com/t/hcsec-2023-15-consul-cluster-peering-can-result-in-denial-of-service/54515.