CVE-2023-6337

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/12/2023
Last modified:
13/02/2025

Description

HashiCorp Vault and Vault Enterprise 1.12.0 and newer are vulnerable to a denial of service through memory exhaustion of the host when handling large unauthenticated and authenticated HTTP requests from a client. Vault will attempt to map the request to memory, resulting in the exhaustion of available memory on the host, which may cause Vault to crash.<br /> <br /> Fixed in Vault 1.15.4, 1.14.8, 1.13.12.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hashicorp:vault:*:*:*:*:*:*:*:* 1.12.0 (including)
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* 1.12.0 (including)
cpe:2.3:a:hashicorp:vault:*:*:*:*:*:*:*:* 1.13.0 (including) 1.13.12 (excluding)
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* 1.13.0 (including) 1.13.12 (excluding)
cpe:2.3:a:hashicorp:vault:*:*:*:*:*:*:*:* 1.14.0 (including) 1.14.8 (excluding)
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* 1.14.0 (including) 1.14.8 (excluding)
cpe:2.3:a:hashicorp:vault:*:*:*:*:*:*:*:* 1.15.0 (including) 1.15.4 (excluding)
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* 1.15.0 (including) 1.15.4 (excluding)