CVE-2023-3462
Published: Jul 31, 2023
Modified: Oct 21, 2024
CVSS v3.1
5.3
Description
HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existent and non-existent LDAP users and observe the response from Vault to check if the account is valid on the LDAP server. This vulnerability is fixed in Vault 1.14.1 and 1.13.5.
| Vendor | Product | Versions |
|---|---|---|
HashiCorp | Vault | affected 1.13.0 - <= 1.13.4affected 1.14.0 |
HashiCorp | Vault Enterprise | affected 1.13.0 - <= 1.13.4affected 1.14.0 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now