Логотип exploitDog
bind: "CVE-2023-3462"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2023-3462"

Количество 4

Количество 4

redhat логотип

CVE-2023-3462

почти 2 года назад

HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existent and non-existent LDAP users and observe the response from Vault to check if the account is valid on the LDAP server. This vulnerability is fixed in Vault 1.14.1 and 1.13.5.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2023-3462

почти 2 года назад

HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existent and non-existent LDAP users and observe the response from Vault to check if the account is valid on the LDAP server. This vulnerability is fixed in Vault 1.14.1 and 1.13.5.

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20241028-01

8 месяцев назад

Уязвимость vault

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-9v3w-w2jh-4hff

почти 2 года назад

HashiCorp Vault and Vault Enterprise vulnerable to user enumeration

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2023-3462

HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existent and non-existent LDAP users and observe the response from Vault to check if the account is valid on the LDAP server. This vulnerability is fixed in Vault 1.14.1 and 1.13.5.

CVSS3: 5.3
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2023-3462

HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existent and non-existent LDAP users and observe the response from Vault to check if the account is valid on the LDAP server. This vulnerability is fixed in Vault 1.14.1 and 1.13.5.

CVSS3: 5.3
1%
Низкий
почти 2 года назад
redos логотип
ROS-20241028-01

Уязвимость vault

CVSS3: 5.3
1%
Низкий
8 месяцев назад
github логотип
GHSA-9v3w-w2jh-4hff

HashiCorp Vault and Vault Enterprise vulnerable to user enumeration

CVSS3: 5.3
1%
Низкий
почти 2 года назад

Уязвимостей на страницу