Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fhc2-8qx8-6vj7

Опубликовано: 26 июн. 2025
Источник: github
Github: Прошло ревью
CVSS3: 3.1

Описание

Vault Community Edition rekey and recovery key operations can cause denial of service

Vault Community and Vault Enterprise rekey and recovery key operations can lead to a denial of service due to uncontrolled cancellation by a Vault operator. This vulnerability (CVE-2025-4656) has been remediated in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11, 1.17.17, and 1.16.22.

Пакеты

Наименование

github.com/hashicorp/vault

go
Затронутые версииВерсия исправления

>= 1.14.8, < 1.20.0

1.20.0

EPSS

Процентиль: 2%
0.00015
Низкий

3.1 Low

CVSS3

Дефекты

CWE-1088

Связанные уязвимости

CVSS3: 3.1
redhat
около 2 месяцев назад

Vault Community and Vault Enterprise rekey and recovery key operations can lead to a denial of service due to uncontrolled cancellation by a Vault operator. This vulnerability (CVE-2025-4656) has been remediated in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11, 1.17.17, and 1.16.22.

CVSS3: 3.1
nvd
около 2 месяцев назад

Vault Community and Vault Enterprise rekey and recovery key operations can lead to a denial of service due to uncontrolled cancellation by a Vault operator. This vulnerability (CVE-2025-4656) has been remediated in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11, 1.17.17, and 1.16.22.

CVSS3: 3.1
redos
около 1 месяца назад

Уязвимость vault

CVSS3: 3.1
fstec
около 2 месяцев назад

Уязвимость платформ для архивирования корпоративной информации HashiCorp Vault Community Edition и Vault Enterprise, связанная с ошибками управления ресурсами, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 2%
0.00015
Низкий

3.1 Low

CVSS3

Дефекты

CWE-1088