#VU99577 Resource exhaustion in Vault and Vault Enterprise - CVE-2024-8185
Published: November 1, 2024
Vault
Vault Enterprise
HashiCorp
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in the Raft cluster join API endpoint. A remote attacker can send multiple HTTP requests to the affected API endpoint and consume all available memory resources.