CVE-2023-1297
Hashicorp Consul 1.13.0 – 1.14.7
Raw vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HSummary
CVE-2023-1297 is a medium-severity Premature Release of Resource During Expected Lifetime (CWE-826) vulnerability in Hashicorp Consul. Its CVSS base score is 4.9 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation for Privilege Escalation (T1068); ranked in the top 48% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-1770
Vulnerability Data
Consul and Consul Enterprise's cluster peering implementation contained a flaw whereby a peer cluster with service of the same name as a local service could corrupt Consul state, resulting in denial of service. This vulnerability was resolved in Consul 1.14.5,…
more
and 1.15.3
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing can detect premature-release bugs, providing partial mitigation.
Secure development lifecycle practices can include resource-lifetime checks that reduce premature-release defects.
Application security requirements can mandate explicit resource-release rules, partially addressing the weakness.
Secure architecture principles encourage proper resource scoping and lifetime management.
Secure coding standards directly prohibit premature resource release, covering most of the weakness.
Change-management processes may catch resource-handling regressions but do not directly prevent the weakness.