Resource exhaustion in Vault Enterprise and Vault - CVE-2023-5954
Published: November 10, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when handling policy requests. A remote attacker can send multiple requests to the application, which trigger policy checks and consume large amounts of memory, leading to a denial of service condition.
Affected software
Vault
IBM Cloud Pak for Watson AIOps
Red Hat OpenShift Container Platform
How to mitigate CVE-2023-5954
Vault - addressed in versions 1.13.10, 1.14.6, 1.15.2
IBM Cloud Pak for Watson AIOps - update to 4.5.0
Red Hat OpenShift Container Platform - update to 4.17.0