MEDIUM🇬🇧 English

CVE-2023-4680

CVSS 6.8v3.1pub. 2023-09-15upd. 2024-11-21

HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even with convergent encryption disabled. The encrypt endpoint, in combination with an offline attack, could be used to decrypt arbitrary ciphertext and potentially derive the authentication subkey when using transit secrets engine without convergent encryption. Introduced in 1.6.0 and fixed in 1.14.3, 1.13.7, and 1.12.11.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
  • Hashicorp Vault

    APP
    Hashicorp
    1.6.0 – 1.12.11 (bez)1.13.0 – 1.13.7 (bez)1.14.0 – 1.14.3 (bez)
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2025-6000CRITICAL9.1PL ✓ten sam produkt

HashiCorp Vault: RCE przez uprzywilejowanego operatora via sys/audit

CVE-2022-40186CRITICAL9.1PL ✓ten sam produkt

HashiCorp Vault: błędne nadpisywanie metadanych aliasów encji

CVE-2022-36129CRITICAL9.1PL ✓ten sam produkt

HashiCorp Vault Enterprise — nieuwierzytelniony endpoint umożliwia manipulację węzłami HA

CVE-2020-35192CRITICAL9.8PL ✓ten sam produkt

Puste hasło root w oficjalnych obrazach Docker HashiCorp Vault

CVE-2020-12757CRITICAL9.8PL ✓ten sam produkt

HashiCorp Vault: nieprawidłowy czas ważności poświadczeń GCP