CVE-2023-5954Missing Release of Memory after Effective Lifetime in Hashicorp Vault

Severity
7.5HIGHNVD
OSV4.3
EPSS
0.6%
top 30.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 9
Latest updateAug 21

Description

HashiCorp Vault and Vault Enterprise inbound client requests triggering a policy check can lead to an unbounded consumption of memory. A large number of these requests may lead to denial-of-service. Fixed in Vault 1.15.2, 1.14.6, and 1.13.10.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

CVEListV5hashicorp/vault_enterprise8 versions+7
NVDhashicorp/vault1.13.71.13.10+2
Gogithub.com/hashicorp_vault1.14.01.14.6+2
CVEListV5hashicorp/vault8 versions+7
Ubuntumozilla/firefox< 111.0.1+build2-0ubuntu0.18.04.1+1

🔴Vulnerability Details

4
OSV
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault2024-08-21
OSV
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability2023-11-09
GHSA
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability2023-11-09
OSV
firefox regressions2023-03-27

📋Vendor Advisories

1
Red Hat
vault: inbound client requests can trigger a denial of service2023-11-09