#VU80812 Security features bypass in Vault and Vault Enterprise - CVE-2023-4680

 

#VU80812 Security features bypass in Vault and Vault Enterprise - CVE-2023-4680

Published: September 15, 2023


Vulnerability identifier: #VU80812
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2023-4680
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Vault
Vault Enterprise
Software vendor:
HashiCorp

Description

The vulnerability allows a remote user to bypass implemented security restrictions.

The vulnerability exists due to an error when enforcing policies related to convergent encryption feature. Software does not restrict the use of user-provided nonces when performing encryption operations on the transit secrets engine when convergent encryption is not enabled. A remote user authorized by Vault policies to encrypt transit data may be able to decrypt arbitrary ciphertext by performing encryption operations using known plaintexts and nonces.


Remediation

Install updates from vendor's website.

External links