CVE-2023-3774

An unhandled error in Vault Enterprise's namespace creation may cause the Vault process to crash, potentially resulting in denial of service. Fixed in 1.14.1, 1.13.5, and 1.12.9.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hashicorp:vault:1.12.8:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:vault:1.13.4:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:vault:1.14.0:*:*:*:enterprise:*:*:*

History

03 Aug 2023, 14:05

Type Values Removed Values Added
CPE cpe:2.3:a:hashicorp:vault:1.12.8:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:vault:1.14.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:vault:1.13.4:*:*:*:enterprise:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.9
First Time Hashicorp
Hashicorp vault
CWE CWE-755
References (MISC) https://discuss.hashicorp.com/t/hcsec-2023-23-vault-enterprise-namespace-creation-may-lead-to-denial-of-service/56617 - (MISC) https://discuss.hashicorp.com/t/hcsec-2023-23-vault-enterprise-namespace-creation-may-lead-to-denial-of-service/56617 - Vendor Advisory

28 Jul 2023, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-28 01:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-3774

Mitre link : CVE-2023-3774

CVE.ORG link : CVE-2023-3774


JSON object : View

Products Affected

hashicorp

  • vault
CWE
CWE-755

Improper Handling of Exceptional Conditions

CWE-703

Improper Check or Handling of Exceptional Conditions