CVE-2023-0845: Hashicorp Consul

Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.

Consul and Consul Enterprise allowed an authenticated user with service:write permissions to trigger a workflow that causes Consul server and client agents to crash under certain circumstances. This vulnerability was fixed in Consul 1.14.5.

Affected products

  • Hashicorp Consul: before 1.14.5 (fixed in 1.14.5)

Published 2023-03-09. Last modified 2026-06-17.