Skip to content
vaultGHSA-v84f-6r39-cpfc

HashiCorp Vault Improper Input Validation vulnerability

Medium6.8CVE-2023-4680 · Published Sep 15, 2023 · updated Aug 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/vault
Go
>= 1.6.0, < 1.12.111.12.11
>= 1.13.0, < 1.13.71.13.7
>= 1.14.0, < 1.14.31.14.3
Details and references

HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even with convergent encryption disabled. The encrypt endpoint, in combination with an offline attack, could be used to decrypt arbitrary ciphertext and potentially derive the authentication subkey when using transit secrets engine without convergent encryption. Introduced in 1.6.0 and fixed in 1.14.3, 1.13.7, and 1.12.11.

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-20, CWE-323
Also known as
BIT-vault-2023-4680, CVE-2023-4680, GO-2023-2063

More vault advisories

All
DateAdvisory
Sep 292023Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability
CVE-2023-5077High7.6fixed in 1.13.0
Aug 12023HashiCorp Vault and Vault Enterprise vulnerable to user enumeration
CVE-2023-3462Medium5.3fixed in 1.13.5, 1.14.1
Nov 92023HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability
CVE-2023-5954High7.5fixed in 1.13.10, 1.14.6, 1.15.2
Jul 62023Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation
CVE-2023-24999High8.1fixed in 1.10.11, 1.11.8, 1.12.4
Jul 62023HashiCorp Vault's revocation list not respected
CVE-2022-41316Medium5.3fixed in 1.9.10, 1.10.7, 1.11.4
Dec 92023Memory exhaustion in HashiCorp Vault
CVE-2023-6337High7.5fixed in 1.13.12, 1.14.8, 1.15.4

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.