Skip to main content

Premature Release of Resource During Expected Lifetime

CVE-2023-1297

Severity High
Score 7.5/10

Summary

Consul and Consul Enterprise's cluster peering implementation contained a flaw in versions 1.13.0-alpha1 through 1.14.6 and 1.15.0 through 1.15.2, whereby a peer cluster with a service of the same name as a local service could corrupt Consul state, resulting in a denial of service.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • HIGH

CWE-826 - Premature Release of Resource During Expected Lifetime

The program releases a resource that is still intended to be used by the program itself or another actor.

Advisory Timeline

  • Published