Consul Server Panic when Ingress and API Gateways Configured with Peering
Published Mar 9, 2023
6.5
MEDIUMCVSS 3.1
EPSS 1.00%
Description
Consul and Consul Enterprise allowed an authenticated user with service:write permissions to trigger a workflow that causes Consul server and client agents to crash under certain circumstances. This vulnerability was fixed in Consul 1.14.5.
Affected products
-
- Version 1.14.0StatusaffectedConstraints-
- Version 1.14.1StatusaffectedConstraints-
- Version 1.14.2StatusaffectedConstraints-
- Version 1.14.3StatusaffectedConstraints-
- Version 1.14.4StatusaffectedConstraints-
- Version
-
- Version 1.14.0StatusaffectedConstraints-
- Version 1.14.1StatusaffectedConstraints-
- Version 1.14.2StatusaffectedConstraints-
- Version 1.14.3StatusaffectedConstraints-
- Version 1.14.4StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| HashiCorp | Consul | unaffected |
| ||||||||||||||||||
| HashiCorp | Consul Enterprise | unaffected |
|
No data.
Logging Subsystem for Red Hat OpenShift
openshift-logging/logging-loki-rhel9
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/acm-grafana-rhel8
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-grafana
Not affected
Red Hat OpenShift Container Platform 4
openshift4/topology-aware-lifecycle-manager-rhel8-operator
Not affected
Red Hat Openshift Data Foundation 4
odf4/odf-multicluster-rhel9-operator
Will not fix
Red Hat Openshift Data Foundation 4
odf4/odr-rhel8-operator
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Logging Subsystem for Red Hat OpenShift | openshift-logging/logging-loki-rhel9 | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/acm-grafana-rhel8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-grafana | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/topology-aware-lifecycle-manager-rhel8-operator | Not affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/odf-multicluster-rhel9-operator | Will not fix | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/odr-rhel8-operator | Affected | n/a |
github.com/hashicorp/consul
Go
Introduced 1.14.0 Fixed 1.14.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/hashicorp/consul | 1.14.0 | 1.14.5 |
Remediation
No remediation recorded yet.
References (9)
- https://access.redhat.com/security/cve/CVE-2023-0845 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2177595 Issue Tracking
- https://discuss.hashicorp.com/t/hcsec-2023-06-consul-server-panic-when-ingress-and-api-gateways-configured-with-peering-connections/51197 Issue TrackingVendor Advisory
- https://github.com/advisories/GHSA-wj6x-hcc2-f32j Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LYZOKMMVX4SIEHPJW3SJUQGMO5YZCPHC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XNF4OLYZRQE75EB5TW5N42FSXHBXGWFE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZTE4ITXXPIWZEQ4HYQCB6N6GZIMWXDAI/
- https://nvd.nist.gov/vuln/detail/CVE-2023-0845
- https://www.cve.org/CVERecord?id=CVE-2023-0845
Change history (0)
No recorded changes yet.