Observable Response Discrepancy in Vault and Vault Enterprise - CVE-2023-3462
Published: August 1, 2023
Vulnerability identifier: #VU78804
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-3462
CWE-ID: CWE-204
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the observable response discrepancy issue in the LDAP auth method. A remote user can enumerate valid accounts.
Affected software
Vault
Vault Enterprise
IBM Cloud Pak for Watson AIOps
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat OpenShift Container Platform
Vault Enterprise
IBM Cloud Pak for Watson AIOps
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat OpenShift Container Platform
How to mitigate CVE-2023-3462
Install updates from vendor's website.
Vault - addressed in versions 1.13.5, 1.14.1
Vault Enterprise - addressed in versions 1.13.5, 1.14.1
IBM Cloud Pak for Watson AIOps - update to 4.2.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.14.0
Red Hat OpenShift Container Platform - addressed in versions 4.16.16, 4.17.1
Vault Enterprise - addressed in versions 1.13.5, 1.14.1
IBM Cloud Pak for Watson AIOps - update to 4.2.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.14.0
Red Hat OpenShift Container Platform - addressed in versions 4.16.16, 4.17.1
External References
Related Security Bulletins
- Information disclosure in HashiCorp Vault and Vault Enterprise
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.14
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17