MEDIUM🇵🇱 Wersja polska

CVE-2023-4680

CVSS 6.8v3.1pub. 2023-09-15upd. 2024-11-21

HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even with convergent encryption disabled. The encrypt endpoint, in combination with an offline attack, could be used to decrypt arbitrary ciphertext and potentially derive the authentication subkey when using transit secrets engine without convergent encryption. Introduced in 1.6.0 and fixed in 1.14.3, 1.13.7, and 1.12.11.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
  • Hashicorp Vault

    APP
    Hashicorp
    1.6.0 – 1.12.11 (excl.)1.13.0 – 1.13.7 (excl.)1.14.0 – 1.14.3 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-6000CRITICAL9.1PL ✓same product

HashiCorp Vault: RCE przez uprzywilejowanego operatora via sys/audit

CVE-2022-40186CRITICAL9.1PL ✓same product

HashiCorp Vault: błędne nadpisywanie metadanych aliasów encji

CVE-2022-36129CRITICAL9.1PL ✓same product

HashiCorp Vault Enterprise — nieuwierzytelniony endpoint umożliwia manipulację węzłami HA

CVE-2020-35192CRITICAL9.8PL ✓same product

Puste hasło root w oficjalnych obrazach Docker HashiCorp Vault

CVE-2020-12757CRITICAL9.8PL ✓same product

HashiCorp Vault: nieprawidłowy czas ważności poświadczeń GCP