HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even with convergent encryption disabled. The encrypt endpoint, in combination with an offline attack, could be used to decrypt arbitrary ciphertext and potentially derive the authentication subkey when using transit secrets engine without convergent encryption. Introduced in 1.6.0 and fixed in 1.14.3, 1.13.7, and 1.12.11.
oryginał ENCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:NHashicorp Vault
APPHashicorp1.6.0 – 1.12.11 (bez)1.13.0 – 1.13.7 (bez)1.14.0 – 1.14.3 (bez)
Powiązane podatności
HashiCorp Vault: RCE przez uprzywilejowanego operatora via sys/audit
HashiCorp Vault: błędne nadpisywanie metadanych aliasów encji
HashiCorp Vault Enterprise — nieuwierzytelniony endpoint umożliwia manipulację węzłami HA
Puste hasło root w oficjalnych obrazach Docker HashiCorp Vault
HashiCorp Vault: nieprawidłowy czas ważności poświadczeń GCP