CVE-2023-0845
MEDIUM6.5EPSS 0.39%Consul Server Panic when Ingress and API Gateways Configured with Peering
Published: 3/9/2023Modified: 5/20/2025
Description
Consul and Consul Enterprise allowed an authenticated user with service:write permissions to trigger a workflow that causes Consul server and client agents to crash under certain circumstances. This vulnerability was fixed in Consul 1.14.5.
Affected packages (3)
- Bitnami/consulfrom 0, < 1.14.5
- Go/github.com/hashicorp/consul>= 1.14.0, < 1.14.5
- Go/github.com/hashicorp/consul>= 1.14.0, < 1.14.5
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
References (10)
- ADVISORYhttps://github.com/advisories/GHSA-wj6x-hcc2-f32j
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2023-0845
- PATCHhttps://github.com/hashicorp/consul
- WEBhttps://discuss.hashicorp.com/t/hcsec-2023-06-consul-server-panic-when-ingress-and-api-gateways-configured-with-peering-connections/51197
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/LYZOKMMVX4SIEHPJW3SJUQGMO5YZCPHC
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/LYZOKMMVX4SIEHPJW3SJUQGMO5YZCPHC/
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/XNF4OLYZRQE75EB5TW5N42FSXHBXGWFE
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/XNF4OLYZRQE75EB5TW5N42FSXHBXGWFE/
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/ZTE4ITXXPIWZEQ4HYQCB6N6GZIMWXDAI
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/ZTE4ITXXPIWZEQ4HYQCB6N6GZIMWXDAI/