vaultGHSA-9v3w-w2jh-4hff
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration
Medium5.3CVE-2023-3462 · Published Aug 1, 2023 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/vault Go | < 1.13.5 | 1.13.5 |
| >= 1.14.0, < 1.14.1 | 1.14.1 |
Details and references
HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existent and non-existent LDAP users and observe the response from Vault to check if the account is valid on the LDAP server. This vulnerability is fixed in Vault 1.14.1 and 1.13.5.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-203
- Also known as
- BIT-vault-2023-3462, CVE-2023-3462, GO-2023-1986
More vault advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 62023 | Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation CVE-2023-24999High8.1fixed in 1.10.11, 1.11.8, 1.12.4 | High8.1 | 1.10.11, 1.11.8, 1.12.4 |
| Jul 62023 | HashiCorp Vault's revocation list not respected CVE-2022-41316Medium5.3fixed in 1.9.10, 1.10.7, 1.11.4 | Medium5.3 | 1.9.10, 1.10.7, 1.11.4 |
| Sep 152023 | HashiCorp Vault Improper Input Validation vulnerability CVE-2023-4680Medium6.8fixed in 1.12.11, 1.13.7, 1.14.3 | Medium6.8 | 1.12.11, 1.13.7, 1.14.3 |
| Jun 92023 | Hashicorp Vault vulnerable to Cross-site Scripting CVE-2023-2121Medium4.3fixed in 1.11.11, 1.12.7, 1.13.3 | Medium4.3 | 1.11.11, 1.12.7, 1.13.3 |
| Sep 292023 | Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability CVE-2023-5077High7.6fixed in 1.13.0 | High7.6 | 1.13.0 |
| Nov 92023 | HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability CVE-2023-5954High7.5fixed in 1.13.10, 1.14.6, 1.15.2 | High7.5 | 1.13.10, 1.14.6, 1.15.2 |