Resource exhaustion in Vault and Vault Enterprise - CVE-2023-6337
Published: December 11, 2023
Vault
Vault Enterprise
HashiCorp
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when handling large unauthenticated and authenticated HTTP requests from a client. A remote attacker can send large HTTP requests to the application, consume all available memory resources and perform a denial of service (DoS) attack.