Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vq4h-9ghm-qmrr

Опубликовано: 30 мар. 2023
Источник: github
Github: Прошло ревью
CVSS3: 4.7

Описание

HashiCorp Vault's implementation of Shamir's secret sharing vulnerable to cache-timing attacks

HashiCorp Vault's implementation of Shamir's secret sharing used precomputed table lookups, and was vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in Vault 1.13.1, 1.12.5, and 1.11.9.

Пакеты

Наименование

github.com/hashicorp/vault

go
Затронутые версииВерсия исправления

< 1.11.9

1.11.9

Наименование

github.com/hashicorp/vault

go
Затронутые версииВерсия исправления

>= 1.12.0, < 1.12.5

1.12.5

Наименование

github.com/hashicorp/vault

go
Затронутые версииВерсия исправления

>= 1.13.0, < 1.13.1

1.13.1

EPSS

Процентиль: 11%
0.00039
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-203
CWE-208

Связанные уязвимости

CVSS3: 5
redhat
около 2 лет назад

HashiCorp Vault's implementation of Shamir's secret sharing used precomputed table lookups, and was vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in Vault 1.13.1, 1.12.5, and 1.11.9.

CVSS3: 5
nvd
около 2 лет назад

HashiCorp Vault's implementation of Shamir's secret sharing used precomputed table lookups, and was vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in Vault 1.13.1, 1.12.5, and 1.11.9.

CVSS3: 4.7
fstec
около 2 лет назад

Уязвимость реализации механизма Shamir’s secret платформ для архивирования корпоративной информации HashiCorp Vault и Vault Enterprise, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 8.1
redos
24 дня назад

Множественные уязвимости vault

EPSS

Процентиль: 11%
0.00039
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-203
CWE-208