Input validation error in Consul and Consul Enterprise - CVE-2023-0845
Published: August 28, 2023
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote user with service:write permissions can configure the upstreams to reference a peering destination and crash the Consul server or client agent hosting the xDS connection to an API gateway or ingress gateway.
Affected software
Consul Enterprise
IBM Cloud Pak for Watson AIOps
Fedora
moby-engine
How to mitigate CVE-2023-0845
Consul Enterprise - update to 1.14.5
moby-engine - addressed in versions 24.0.5-1.fc37, 24.0.5-1.fc38, 24.0.5-1.fc39