Observable Response Discrepancy in Vault and Vault Enterprise - CVE-2023-3462

 

Observable Response Discrepancy in Vault and Vault Enterprise - CVE-2023-3462

Published: August 1, 2023


Vulnerability identifier: #VU78804
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-3462
CWE-ID: CWE-204
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the observable response discrepancy issue in the LDAP auth method. A remote user can enumerate valid accounts.


Affected software

Vault
Vault Enterprise
IBM Cloud Pak for Watson AIOps
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat OpenShift Container Platform

How to mitigate CVE-2023-3462

Install updates from vendor's website.

Vault - addressed in versions 1.13.5, 1.14.1
Vault Enterprise - addressed in versions 1.13.5, 1.14.1
IBM Cloud Pak for Watson AIOps - update to 4.2.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.14.0
Red Hat OpenShift Container Platform - addressed in versions 4.16.16, 4.17.1

External References

Related Security Bulletins