consulGHSA-c57c-7hrj-6q6v
Hashicorp Consul vulnerable to denial of service
Medium4.9CVE-2023-1297 · Published Jun 3, 2023 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/consul Go | < 1.14.5 | 1.14.5 |
| >= 1.15.0, < 1.15.3 | 1.15.3 |
Details and references
Consul and Consul Enterprise's cluster peering implementation contained a flaw whereby a peer cluster with service of the same name as a local service could corrupt Consul state, resulting in denial of service. This vulnerability was resolved in Consul 1.14.5, and 1.15.3
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-826
- Also known as
- BIT-consul-2023-1297, CVE-2023-1297, GO-2023-1827
More consul advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 32023 | Hashicorp Consul allows user with service:write permissions to patch remote proxy instances CVE-2023-2816High8.7fixed in 1.15.3 | High8.7 | 1.15.3 |
| Jun 92023 | HashiCorp Consul Incorrect Access Control vulnerability CVE-2019-12291High7.5fixed in 1.5.1 | High7.5 | 1.5.1 |
| Aug 92023 | Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers CVE-2023-3518High7.4fixed in 1.16.1 | High7.4 | 1.16.1 |
| Mar 92023 | Consul Server Panic when Ingress and API Gateways Configured with Peering Connections CVE-2023-0845Medium6.5fixed in 1.14.5 | Medium6.5 | 1.14.5 |
| Nov 162022 | Missing Authorization in HashiCorp Consul CVE-2022-3920High7.5fixed in 1.14.0 | High7.5 | 1.14.0 |
| Jan 312024 | Denial of service in HashiCorp Consul CVE-2020-25201High7.5fixed in 1.7.9, 1.8.5 | High7.5 | 1.7.9, 1.8.5 |