CVE Database
/

CVE-2023-0620

Back to search

CVE-2023-0620

Published: Mar 30, 2023

Modified: Feb 13, 2025

PUBLISHED

CVSS v3.1

6.5

MEDIUM

Description

HashiCorp Vault and Vault Enterprise versions 0.8.0 through 1.13.1 are vulnerable to an SQL injection attack when configuring the Microsoft SQL (MSSQL) Database Storage Backend. When configuring the MSSQL plugin through the local, certain parameters are not sanitized when passed to the user-provided MSSQL database. An attacker may modify these parameters to execute a malicious SQL command. This issue is fixed in versions 1.13.1, 1.12.5, and 1.11.9.

VendorProductVersions

HashiCorp

Vault

affected
1.13.0 - < 1.13.1
affected
1.12.0 - < 1.12.5
affected
0.8.0 - < 1.11.9

HashiCorp

Vault Enterprise

affected
1.13.0 - < 1.13.1
affected
1.12.0 - < 1.12.5
affected
0.8.0 - < 1.11.9

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

Low

Privileges Required

High

User Interaction

Required

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now