vaultGHSA-v84f-6r39-cpfc
HashiCorp Vault Improper Input Validation vulnerability
Medium6.8CVE-2023-4680 · Published Sep 15, 2023 · updated Aug 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/vault Go | >= 1.6.0, < 1.12.11 | 1.12.11 |
| >= 1.13.0, < 1.13.7 | 1.13.7 | |
| >= 1.14.0, < 1.14.3 | 1.14.3 |
Details and references
HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even with convergent encryption disabled. The encrypt endpoint, in combination with an offline attack, could be used to decrypt arbitrary ciphertext and potentially derive the authentication subkey when using transit secrets engine without convergent encryption. Introduced in 1.6.0 and fixed in 1.14.3, 1.13.7, and 1.12.11.
More vault advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 292023 | Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability CVE-2023-5077High7.6fixed in 1.13.0 | High7.6 | 1.13.0 |
| Aug 12023 | HashiCorp Vault and Vault Enterprise vulnerable to user enumeration CVE-2023-3462Medium5.3fixed in 1.13.5, 1.14.1 | Medium5.3 | 1.13.5, 1.14.1 |
| Nov 92023 | HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability CVE-2023-5954High7.5fixed in 1.13.10, 1.14.6, 1.15.2 | High7.5 | 1.13.10, 1.14.6, 1.15.2 |
| Jul 62023 | Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation CVE-2023-24999High8.1fixed in 1.10.11, 1.11.8, 1.12.4 | High8.1 | 1.10.11, 1.11.8, 1.12.4 |
| Jul 62023 | HashiCorp Vault's revocation list not respected CVE-2022-41316Medium5.3fixed in 1.9.10, 1.10.7, 1.11.4 | Medium5.3 | 1.9.10, 1.10.7, 1.11.4 |
| Dec 92023 | Memory exhaustion in HashiCorp Vault CVE-2023-6337High7.5fixed in 1.13.12, 1.14.8, 1.15.4 | High7.5 | 1.13.12, 1.14.8, 1.15.4 |