Vulnerability Details CVE-2023-1297
Consul and Consul Enterprise's cluster peering implementation contained a flaw whereby a peer cluster with service of the same name as a local service could corrupt Consul state, resulting in denial of service. This vulnerability was resolved in Consul 1.14.5, and 1.15.3
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 38.1%
CVSS Severity
CVSS v3 Score 4.9
Products affected by CVE-2023-1297
-
cpe:2.3:a:hashicorp:consul:1.13.0
-
cpe:2.3:a:hashicorp:consul:1.13.1
-
cpe:2.3:a:hashicorp:consul:1.13.2
-
cpe:2.3:a:hashicorp:consul:1.13.3
-
cpe:2.3:a:hashicorp:consul:1.14.0
-
cpe:2.3:a:hashicorp:consul:1.15.0