Resource exhaustion in Vault Enterprise and Vault - CVE-2024-8185

 

Resource exhaustion in Vault Enterprise and Vault - CVE-2024-8185

Published: November 1, 2024


Vulnerability identifier: #VU99577
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-8185
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources in the Raft cluster join API endpoint. A remote attacker can send multiple HTTP requests to the affected API endpoint and consume all available memory resources.


Affected software

Vault Enterprise
Vault
IBM Cloud Pak for Watson AIOps

How to mitigate CVE-2024-8185

Install updates from vendor's website.

Vault Enterprise - addressed in versions 1.16.12, 1.17.8, 1.18.1
Vault - update to 1.18.1
IBM Cloud Pak for Watson AIOps - update to 4.8.1

External References

Related Security Bulletins