Resource exhaustion in Vault Enterprise and Vault - CVE-2024-8185
Published: November 1, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in the Raft cluster join API endpoint. A remote attacker can send multiple HTTP requests to the affected API endpoint and consume all available memory resources.
Affected software
Vault
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2024-8185
Vault - update to 1.18.1
IBM Cloud Pak for Watson AIOps - update to 4.8.1