PT-2023-2223 · Hashicorp+2 · Hashicorp Consul+3

CVE-2023-0845

·

Publicado

2023-03-07

·

Atualizado

2024-08-20

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Consul versions prior to 1.14.5 Consul Enterprise versions prior to 1.14.5
Description The issue is related to an authenticated user with service:write permissions triggering a workflow that causes the Consul server and client agents to crash under certain circumstances. To exploit this, an attacker requires access to an ACL token with service:write permissions and at least one running ingress or API gateway configured to route traffic to an upstream service. The vulnerability is also associated with pointer dereference errors.
Recommendations For Consul versions prior to 1.14.5, update to Consul 1.14.5 to resolve the issue. For Consul Enterprise versions prior to 1.14.5, update to Consul Enterprise 1.14.5 to resolve the issue. As a temporary workaround, consider restricting access to service:write permissions to minimize the risk of exploitation. Restrict access to ingress or API gateways that are configured to route traffic to an upstream service until the issue is resolved.

Exploit

Correção

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-1696
ALT-PU-2023-7106
ALT-PU-2024-8028
BDU:2023-01973
BIT-CONSUL-2023-0845
CVE-2023-0845
GHSA-WJ6X-HCC2-F32J
GO-2023-1639

Produtos afetados

Alt Linux
Hashicorp Consul
Hashicorp Consul Enterprise
Red Os