Information disclosure in Vault Enterprise and Vault - CVE-2023-25000

 

Information disclosure in Vault Enterprise and Vault - CVE-2023-25000

Published: March 30, 2023


Vulnerability identifier: #VU74186
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-25000
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the Shamir implementation uses precomputed table lookups. A remote user can perform a cache-timing attack and recover the Shamir shares.


Affected software

Vault Enterprise
Vault
Storage Fusion Data Foundation
Cloud Pak for Network Automation
Red Hat OpenShift Container Platform
OpenShift Data Foundation (formerly OpenShift Container Storage)

How to mitigate CVE-2023-25000

Install updates from vendor's website.

Vault Enterprise - addressed in versions 1.11.9, 1.12.5, 1.13.1
Vault - addressed in versions 1.11.9, 1.12.5, 1.13.1
Storage Fusion Data Foundation - update to 4.13
Cloud Pak for Network Automation - update to 2.4.7
Red Hat OpenShift Container Platform - update to 4.13.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0

External References

Related Security Bulletins