Vulnerability Description
HashiCorp Vault and Vault Enterprise inbound client requests triggering a policy check can lead to an unbounded consumption of memory. A large number of these requests may lead to denial-of-service. Fixed in Vault 1.15.2, 1.14.6, and 1.13.10.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hashicorp | Vault | >= 1.13.7, < 1.13.10 |
Related Weaknesses (CWE)
References
- https://discuss.hashicorp.com/t/hcsec-2023-33-vault-requests-triggering-policy-cVendor Advisory
- https://security.netapp.com/advisory/ntap-20231227-0001/
- https://discuss.hashicorp.com/t/hcsec-2023-33-vault-requests-triggering-policy-cVendor Advisory
- https://security.netapp.com/advisory/ntap-20231227-0001/
FAQ
What is CVE-2023-5954?
CVE-2023-5954 is a vulnerability with a CVSS score of 5.9 (MEDIUM). HashiCorp Vault and Vault Enterprise inbound client requests triggering a policy check can lead to an unbounded consumption of memory. A large number of these requests may lead to denial-of-service. F...
How severe is CVE-2023-5954?
CVE-2023-5954 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-5954?
Check the references section above for vendor advisories and patch information. Affected products include: Hashicorp Vault.