Input validation error in Vault and Vault Enterprise - CVE-2023-0665

 

Input validation error in Vault and Vault Enterprise - CVE-2023-0665

Published: March 30, 2023


Vulnerability identifier: #VU74184
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-0665
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to the PKI mount issuer endpoints do not correctly authorize access to remove an issuer or modify issuer metadata. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

Vault
Vault Enterprise
Cloud Pak for Network Automation
Storage Fusion Data Foundation
Red Hat OpenShift Container Platform
OpenShift Data Foundation (formerly OpenShift Container Storage)

How to mitigate CVE-2023-0665

Install updates from vendor's website.

Vault - addressed in versions 1.11.9, 1.12.5, 1.13.1
Vault Enterprise - addressed in versions 1.11.9, 1.12.5, 1.13.1
Cloud Pak for Network Automation - update to 2.4.7
Red Hat OpenShift Container Platform - update to 4.13.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
Storage Fusion Data Foundation - update to 4.13

External References

Related Security Bulletins