Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-5954

Опубликовано: 09 нояб. 2023
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

HashiCorp Vault and Vault Enterprise inbound client requests triggering a policy check can lead to an unbounded consumption of memory. A large number of these requests may lead to denial-of-service. Fixed in Vault 1.15.2, 1.14.6, and 1.13.10.

A flaw was found in The HashiCorp Vault, which may be susceptible to a denial of service due to an unbounded consumption of memory when handling policy requests. This issue may allow an attacker to trigger policy checks by sending multiple inbound client requests that create a logger that is never removed from memory, leading to excessive memory consumption, causing a denial of service condition.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Openshift Data Foundation 4odf4/ocs-rhel9-operatorNot affected
Red Hat Openshift Data Foundation 4odf4/odf-multicluster-rhel9-operatorNot affected
Red Hat Openshift Data Foundation 4odf4/odf-rhel8-operatorWill not fix
Red Hat Openshift Data Foundation 4odf4/odr-rhel8-operatorNot affected
Red Hat Openshift Data Foundation 4odf4/rook-ceph-rhel8-operatorNot affected
Red Hat OpenShift Container Platform 4.17openshift4/ose-installer-rhel9FixedRHSA-2024:371801.10.2024
RHODF-4.15-RHEL-9odf4/mcg-rhel9-operatorFixedRHSA-2024:138319.03.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-401
https://bugzilla.redhat.com/show_bug.cgi?id=2249115vault: inbound client requests can trigger a denial of service

EPSS

Процентиль: 58%
0.00371
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
nvd
больше 1 года назад

HashiCorp Vault and Vault Enterprise inbound client requests triggering a policy check can lead to an unbounded consumption of memory. A large number of these requests may lead to denial-of-service. Fixed in Vault 1.15.2, 1.14.6, and 1.13.10.

CVSS3: 7.5
github
больше 1 года назад

HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability

CVSS3: 7.5
fstec
больше 1 года назад

Уязвимость платформ для архивирования корпоративной информации HashiCorp Vault и Vault Enterprise, связанная с ошибками освобождения памяти, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.1
redos
11 месяцев назад

Множественные уязвимости vault

EPSS

Процентиль: 58%
0.00371
Низкий

5.9 Medium

CVSS3