CVE-2023-1297
Consul vulnerability analysis and mitigation

Overview

A vulnerability (CVE-2023-1297) was identified in HashiCorp Consul and Consul Enterprise's cluster peering implementation where a peer cluster with a service sharing the same name as a local service could corrupt Consul state, resulting in denial of service. The vulnerability was discovered during internal testing and affected versions 1.13.0 through 1.14.0, and 1.15.0. The issue was resolved in Consul versions 1.14.5, and 1.15.3 (HashiCorp Discuss).

Technical details

The vulnerability exists in Consul's cluster peering feature, which is designed to support peering connections between two or more independent clusters for service communication across different partitions or datacenters. The specific issue occurs when a local and imported service share the same name, and the service on the cluster peer is deleted, leading to state corruption in Consul (HashiCorp Discuss).

Impact

Successful exploitation of this vulnerability results in denial of service, affecting the availability of the Consul cluster. The corruption of Consul's state can disrupt service discovery and communication between services across peered clusters (HashiCorp Discuss).

Mitigation and workarounds

Administrators should upgrade their Consul clusters to version 1.14.5, 1.15.3, or newer to address this vulnerability. It's worth noting that cluster peering was a beta feature in Consul 1.13.x, and the fix was only implemented in the 1.14.x and 1.15.x branches (HashiCorp Discuss).

Additional resources


SourceThis report was generated using AI

Related Consul vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-11375MEDIUM6.5
  • ConsulConsul
  • consul-fips-1.18
NoYesOct 28, 2025
CVE-2025-11374MEDIUM6.5
  • ConsulConsul
  • github.com/hashicorp/consul
NoYesOct 28, 2025
CVE-2024-10086MEDIUM6.1
  • ConsulConsul
  • consul-fips-1.21
NoYesOct 30, 2024
CVE-2024-10006MEDIUM5.8
  • ConsulConsul
  • cpe:2.3:a:hashicorp:consul
NoYesOct 30, 2024
CVE-2024-10005MEDIUM5.8
  • ConsulConsul
  • govulncheck-vulndb
NoYesOct 30, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management