#VU82954 Resource exhaustion in Vault and Vault Enterprise - CVE-2023-5954
Published: November 10, 2023
Vault
Vault Enterprise
HashiCorp
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when handling policy requests. A remote attacker can send multiple requests to the application, which trigger policy checks and consume large amounts of memory, leading to a denial of service condition.