CVE-2023-6337
08.12.2023, 22:15
HashiCorp Vault and Vault Enterprise 1.12.0 and newer are vulnerable to a denial of service through memory exhaustion of the host when handling large unauthenticated and authenticated HTTP requests from a client. Vault will attempt to map the request to memory, resulting in the exhaustion of available memory on the host, which may cause Vault to crash. Fixed inVault 1.15.4, 1.14.8, 1.13.12.Enginsight
| Vendor | Product | Version |
|---|---|---|
| hashicorp | vault | 𝑥 ≤ 1.12.0 |
| hashicorp | vault | 𝑥 ≤ 1.12.0 |
| hashicorp | vault | 1.13.0 ≤ 𝑥 < 1.13.12 |
| hashicorp | vault | 1.13.0 ≤ 𝑥 < 1.13.12 |
| hashicorp | vault | 1.14.0 ≤ 𝑥 < 1.14.8 |
| hashicorp | vault | 1.14.0 ≤ 𝑥 < 1.14.8 |
| hashicorp | vault | 1.15.0 ≤ 𝑥 < 1.15.4 |
| hashicorp | vault | 1.15.0 ≤ 𝑥 < 1.15.4 |
𝑥
= Vulnerable software versions
References