← Vulnerability feed

Vulnerability record · CVE-2023-1297 · published 2 June 2023

CVE-2023-1297: Hashicorp consul vulnerability

Hashicorp · Consul

Consul and Consul Enterprise's cluster peering implementation contained a flaw whereby a peer cluster with service of the same name as a local service could corrupt Consul state, resulting in denial of service. This vulnerability was resolved in Consul 1.14.5, and 1.15.3

7.5 CVSS 3.1 High EPSS 0.77% · top 46.2% CWE-826 · CWE-826
7.5CVSS 3.1 base score
0.77%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Consul and Consul Enterprise's cluster peering implementation contained a flaw whereby a peer cluster with service of the same name as a local service could corrupt Consul state, resulting in denial of service. This vulnerability was resolved in Consul 1.14.5, and 1.15.3

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-1297 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2021-41805Hashicorp consul incorrect authorization vulnerabilityHashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default…EPSS 35%8.8CVE-2021-37219Hashicorp consul improper certificate validation vulnerabilityHashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server…EPSS 1.1%8.6CVE-2021-3121Golang protobuf vulnerabilityAn issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka the "skippy peanut butter" i…EPSS 3.5%8.1CVE-2023-5332Gitlab vulnerabilityPatch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without th…EPSS 0.74%8.1CVE-2019-8336Hashicorp consul vulnerabilityHashiCorp Consul (and Consul Enterprise) 1.4.x before 1.4.3 allows a client to bypass intended access restrictions and obtain the privileges of one o…EPSS 1.3%7.5CVE-2022-3920Hashicorp consul missing authorization vulnerabilityHashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints us…EPSS 0.70%7.5CVE-2022-29153Hashicorp consul server-side request forgery (ssrf) vulnerabilityHashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows re…EPSS 8.7%7.5CVE-2021-32574Hashicorp consul improper certificate validation vulnerabilityHashiCorp Consul and Consul Enterprise 1.3.0 through 1.10.0 Envoy proxy TLS configuration does not validate destination service identity in the encod…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2023-1297), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.