HashiCorp Vault and Vault Enterprise inbound client requests triggering a policy check can lead to an unbounded consumption of memory. A large number of these requests may lead to denial-of-service. Fixed in Vault 1.15.2, 1.14.6, and 1.13.10.
2023-11-09T21:15:25.143
2024-11-21T08:42:51.270
Modified
CVSSv3.1: 5.9 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | hashicorp | vault | < 1.13.10 | Yes |
Application | hashicorp | vault | < 1.13.10 | Yes |
Application | hashicorp | vault | < 1.14.6 | Yes |
Application | hashicorp | vault | < 1.14.6 | Yes |
Application | hashicorp | vault | < 1.15.2 | Yes |
Application | hashicorp | vault | < 1.15.2 | Yes |