CVE-2023-5954
09.11.2023, 21:15
HashiCorp Vault and Vault Enterprise inbound client requests triggering a policy check can lead to an unbounded consumption of memory. A large number of these requests may lead to denial-of-service. Fixed in Vault 1.15.2, 1.14.6, and 1.13.10.Enginsight
Vendor | Product | Version |
---|---|---|
hashicorp | vault | 1.13.7 ≤ 𝑥 < 1.13.10 |
hashicorp | vault | 1.13.7 ≤ 𝑥 < 1.13.10 |
hashicorp | vault | 1.14.3 ≤ 𝑥 < 1.14.6 |
hashicorp | vault | 1.14.3 ≤ 𝑥 < 1.14.6 |
hashicorp | vault | 1.15.0 ≤ 𝑥 < 1.15.2 |
hashicorp | vault | 1.15.0 ≤ 𝑥 < 1.15.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References