Security features bypass in Vault Enterprise and Vault - CVE-2023-4680
Published: September 15, 2023
Vulnerability details
The vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists due to an error when enforcing policies related to convergent encryption feature. Software does not restrict the use of user-provided nonces when performing encryption operations on the transit secrets engine when convergent encryption is not enabled. A remote user authorized by Vault policies to encrypt transit data may be able to decrypt arbitrary ciphertext by performing encryption operations using known plaintexts and nonces.
Affected software
Vault
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2023-4680
Vault - addressed in versions 1.12.11, 1.13.7, 1.14.3
IBM Cloud Pak for Watson AIOps - update to 4.2.1