Consul and Consul Enterprise's cluster peering implementation contained a flaw whereby a peer cluster with service of the same name as a local service could corrupt Consul state, resulting in denial of service. This vulnerability was resolved in Consul 1.14.5, and 1.15.3
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/hashicorp/consul(Go) | 0 | 1.14.5 | N/A |
| github.com/hashicorp/consul(Go) | 1.15.0 | 1.15.3 | N/A |
CVSS Metrics