ConsulGHSA-wj6x-hcc2-f32j
Consul Server Panic when Ingress and API Gateways Configured with Peering Connections
Medium6.5CVE-2023-0845 · Published Mar 9, 2023 · updated Aug 7, 2026
A vulnerability was identified in Consul and Consul Enterprise (“Consul”) an authenticated user with service:write permissions could trigger a workflow that causes Consul server and client agents to crash under certain circumstances. To exploit this vulnerability, an attacker requires access to an ACL token with service:write permissions, and there needs to be at least one running ingress or API gateway that is configured to route traffic to an upstream service.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/consul Go | >= 1.14.0, < 1.14.5 | 1.14.5 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-476
- Also known as
- BIT-consul-2023-0845, CVE-2023-0845, GO-2023-1639
- nvd.nist.gov/vuln/detail/CVE-2023-0845
- discuss.hashicorp.com/t/hcsec-2023-06-consul-server-panic-when-ingress-and-api-gateways-configured-with-peering-connections/51197
- github.com/hashicorp/consul
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LYZOKMMVX4SIEHPJW3SJUQGMO5YZCPHC
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XNF4OLYZRQE75EB5TW5N42FSXHBXGWFE
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZTE4ITXXPIWZEQ4HYQCB6N6GZIMWXDAI
More Consul advisories
All Consul| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 92023 | Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers | High7.4 | 1.16.1 |
| Jun 92023 | HashiCorp Consul Incorrect Access Control vulnerability | High7.5 | 1.5.1 |
| Jun 32023 | Hashicorp Consul allows user with service:write permissions to patch remote proxy instances | High8.7 | 1.15.3 |
| Jun 32023 | Hashicorp Consul vulnerable to denial of service | Medium4.9 | 1.14.5+1 more |
| Nov 162022 | Missing Authorization in HashiCorp Consul | High7.5 | 1.14.0 |
| Sep 252022 | HashiCorp Consul vulnerable to authorization bypass | Medium6.5 | 1.11.9+2 more |