Описание
Vault Community and Vault Enterprise rekey and recovery key operations can lead to a denial of service due to uncontrolled cancellation by a Vault operator. This vulnerability (CVE-2025-4656) has been remediated in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11, 1.17.17, and 1.16.22.
A key handling flaw has been discovered in Vault. The rekey and recovery key operations may lead to a denial of service in the vault application due to uncontrolled cancellations of these operations.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
cert-manager Operator for Red Hat OpenShift | cert-manager/cert-manager-operator-rhel9 | Fix deferred | ||
Red Hat Openshift Data Foundation 4 | odf4/cephcsi-rhel9 | Fix deferred | ||
Red Hat Openshift Data Foundation 4 | odf4/mcg-cli-rhel9 | Fix deferred | ||
Red Hat Openshift Data Foundation 4 | odf4/mcg-rhel9-operator | Fix deferred | ||
Red Hat Openshift Data Foundation 4 | odf4/odf-cli-rhel9 | Fix deferred | ||
Red Hat Trusted Artifact Signer | rhtas/client-server-rhel9 | Fix deferred | ||
Red Hat Trusted Artifact Signer | rhtas/fulcio-rhel9 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
3.1 Low
CVSS3
Связанные уязвимости
Vault Community and Vault Enterprise rekey and recovery key operations can lead to a denial of service due to uncontrolled cancellation by a Vault operator. This vulnerability (CVE-2025-4656) has been remediated in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11, 1.17.17, and 1.16.22.
Vault Community Edition rekey and recovery key operations can cause denial of service
Уязвимость платформ для архивирования корпоративной информации HashiCorp Vault Community Edition и Vault Enterprise, связанная с ошибками управления ресурсами, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
3.1 Low
CVSS3