PT-2023-7600 · Hashicorp+2 · Vault Enterprise+3

CVE-2023-6337

·

Publicado

2023-11-27

·

Atualizado

2024-08-05

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions HashiCorp Vault and Vault Enterprise versions 1.12.0 through 1.15.3 HashiCorp Vault and Vault Enterprise versions 1.13.0 through 1.13.11 HashiCorp Vault and Vault Enterprise versions 1.14.0 through 1.14.7
Description The issue is related to the handling of large unauthenticated and authenticated HTTP requests from a client, which can lead to memory exhaustion of the host. When such requests are made, the software attempts to map them to memory, resulting in the depletion of available memory on the host. This can cause the software to crash, leading to a denial of service.
Recommendations For HashiCorp Vault and Vault Enterprise versions 1.12.0 through 1.15.3, update to version 1.15.4 or newer. For HashiCorp Vault and Vault Enterprise versions 1.13.0 through 1.13.11, update to version 1.13.12 or newer. For HashiCorp Vault and Vault Enterprise versions 1.14.0 through 1.14.7, update to version 1.14.8 or newer.

Exploit

Correção

DoS

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2024-3459
ALT-PU-2024-3678
ALT-PU-2024-3988
ALT-PU-2024-4187
AZL-34585
BDU:2023-08660
BIT-VAULT-2023-6337
CVE-2023-6337
GHSA-6P62-6CG9-F5F5
GO-2023-2399

Produtos afetados

Alt Linux
Hashicorp Vault
Red Os
Vault Enterprise