Vulnerability Description
Consul and Consul Enterprise's cluster peering implementation contained a flaw whereby a peer cluster with service of the same name as a local service could corrupt Consul state, resulting in denial of service. This vulnerability was resolved in Consul 1.14.5, and 1.15.3
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hashicorp | Consul | >= 1.13.0, < 1.14.7 |
Related Weaknesses (CWE)
References
- https://discuss.hashicorp.com/t/hcsec-2023-15-consul-cluster-peering-can-result-Vendor Advisory
- https://discuss.hashicorp.com/t/hcsec-2023-15-consul-cluster-peering-can-result-Vendor Advisory
FAQ
What is CVE-2023-1297?
CVE-2023-1297 is a vulnerability with a CVSS score of 4.9 (MEDIUM). Consul and Consul Enterprise's cluster peering implementation contained a flaw whereby a peer cluster with service of the same name as a local service could corrupt Consul state, resulting in denial o...
How severe is CVE-2023-1297?
CVE-2023-1297 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-1297?
Check the references section above for vendor advisories and patch information. Affected products include: Hashicorp Consul.