GHSA-4qhc-v8r6-8vwm
Dashboard / Vulnerabilities / GHSA-4qhc-v8r6-8vwm
GHSA-4qhc-v8r6-8vwm
Summary: HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability
Details: HashiCorp Vault and Vault Enterprise inbound client requests triggering a policy check can lead to an unbounded consumption of memory. A large number of these requests may lead to denial-of-service. Fixed in Vault 1.15.2, 1.14.6, and 1.13.10.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-5954, https://discuss.hashicorp.com/t/hcsec-2023-33-vault-requests-triggering-policy-checks-may-lead-to-unbounded-memory-consumption/59926, https://github.com/hashicorp/vault, https://security.netapp.com/advisory/ntap-20231227-0001
Affected packages
Package
Name: github.com/hashicorp/vault
Purl: pkg:golang/github.com/hashicorp/vault
Affected ranges
Type: SEMVER
Events:
