Description
HashiCorp Vault and Vault Enterprise inbound client requests triggering a policy check can lead to an unbounded consumption of memory. A large number of these requests may lead to denial-of-service. Fixed in Vault 1.15.2, 1.14.6, and 1.13.10.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2881 | HashiCorp Vault and Vault Enterprise inbound client requests triggering a policy check can lead to an unbounded consumption of memory. A large number of these requests may lead to denial-of-service. Fixed in Vault 1.15.2, 1.14.6, and 1.13.10. |
Github GHSA |
GHSA-4qhc-v8r6-8vwm | HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability |
References
History
Wed, 02 Oct 2024 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat openshift
|
|
| CPEs | cpe:/a:redhat:openshift:4.17::el9 | |
| Vendors & Products |
Redhat openshift
|
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2025-02-13T17:25:58.499Z
Reserved: 2023-11-03T16:18:00.469Z
Link: CVE-2023-5954
No data.
Status : Modified
Published: 2023-11-09T21:15:25.143
Modified: 2024-11-21T08:42:51.270
Link: CVE-2023-5954
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA