Vulnerabilities > CVE-2023-0845 - NULL Pointer Dereference vulnerability in Hashicorp Consul

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
hashicorp
CWE-476

Summary

Consul and Consul Enterprise allowed an authenticated user with service:write permissions to trigger a workflow that causes Consul server and client agents to crash under certain circumstances. This vulnerability was fixed in Consul 1.14.5.

Vulnerable Configurations

Part Description Count
Application
Hashicorp
204

Common Weakness Enumeration (CWE)