Skip to content
vaultGHSA-9v3w-w2jh-4hff

HashiCorp Vault and Vault Enterprise vulnerable to user enumeration

Medium5.3CVE-2023-3462 · Published Aug 1, 2023 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/vault
Go
< 1.13.51.13.5
>= 1.14.0, < 1.14.11.14.1
Details and references

HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existent and non-existent LDAP users and observe the response from Vault to check if the account is valid on the LDAP server. This vulnerability is fixed in Vault 1.14.1 and 1.13.5.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-203
Also known as
BIT-vault-2023-3462, CVE-2023-3462, GO-2023-1986

More vault advisories

All
DateAdvisory
Jul 62023Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation
CVE-2023-24999High8.1fixed in 1.10.11, 1.11.8, 1.12.4
Jul 62023HashiCorp Vault's revocation list not respected
CVE-2022-41316Medium5.3fixed in 1.9.10, 1.10.7, 1.11.4
Sep 152023HashiCorp Vault Improper Input Validation vulnerability
CVE-2023-4680Medium6.8fixed in 1.12.11, 1.13.7, 1.14.3
Jun 92023Hashicorp Vault vulnerable to Cross-site Scripting
CVE-2023-2121Medium4.3fixed in 1.11.11, 1.12.7, 1.13.3
Sep 292023Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability
CVE-2023-5077High7.6fixed in 1.13.0
Nov 92023HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability
CVE-2023-5954High7.5fixed in 1.13.10, 1.14.6, 1.15.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.