Consul and Consul Enterprise's cluster peering implementation contained a flaw whereby a peer cluster with service of the same name as a local service could corrupt Consul state, resulting in denial of service. This vulnerability was resolved in Consul 1.14.5, and 1.15.3
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/1xxx/CVE-2023-1297.json",
"cna_assigner": "HashiCorp",
"cwe_ids": [
"CWE-826"
]
}{
"cpe": [
"cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:*",
"cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*"
],
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "1.13.0"
},
{
"fixed": "1.14.7"
},
{
"introduced": "1.15.0"
},
{
"fixed": "1.15.3"
}
]
}