Back

MEDIUM

Consul Server Panic when Ingress and API Gateways Configured with Peering

Published Mar 9, 2023

Description

Consul and Consul Enterprise allowed an authenticated user with service:write permissions to trigger a workflow that causes Consul server and client agents to crash under certain circumstances. This vulnerability was fixed in Consul 1.14.5.

Affected products

Remediation

No remediation recorded yet.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner HashiCorp
Published Mar 9, 2023
Updated Feb 28, 2025
Reserved Feb 15, 2023
CISA Vulnrichment
Updated Feb 28, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 9, 2023
GHSA-WJ6X-HCC2-F32J