Логотип exploitDog
bind:CVE-2023-3462
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-3462

Количество 4

Количество 4

redhat логотип

CVE-2023-3462

около 2 лет назад

HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existent and non-existent LDAP users and observe the response from Vault to check if the account is valid on the LDAP server. This vulnerability is fixed in Vault 1.14.1 and 1.13.5.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2023-3462

около 2 лет назад

HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existent and non-existent LDAP users and observe the response from Vault to check if the account is valid on the LDAP server. This vulnerability is fixed in Vault 1.14.1 and 1.13.5.

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20241028-01

11 месяцев назад

Уязвимость vault

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-9v3w-w2jh-4hff

около 2 лет назад

HashiCorp Vault and Vault Enterprise vulnerable to user enumeration

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2023-3462

HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existent and non-existent LDAP users and observe the response from Vault to check if the account is valid on the LDAP server. This vulnerability is fixed in Vault 1.14.1 and 1.13.5.

CVSS3: 5.3
1%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-3462

HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existent and non-existent LDAP users and observe the response from Vault to check if the account is valid on the LDAP server. This vulnerability is fixed in Vault 1.14.1 and 1.13.5.

CVSS3: 5.3
1%
Низкий
около 2 лет назад
redos логотип
ROS-20241028-01

Уязвимость vault

CVSS3: 5.3
1%
Низкий
11 месяцев назад
github логотип
GHSA-9v3w-w2jh-4hff

HashiCorp Vault and Vault Enterprise vulnerable to user enumeration

CVSS3: 5.3
1%
Низкий
около 2 лет назад

Уязвимостей на страницу