Skip to content
vaultGHSA-vq4h-9ghm-qmrr

HashiCorp Vault's implementation of Shamir's secret sharing vulnerable to cache-timing attacks

Medium4.7CVE-2023-25000 · Published Mar 30, 2023 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/vault
Go
< 1.11.91.11.9
>= 1.12.0, < 1.12.51.12.5
>= 1.13.0, < 1.13.11.13.1
Details and references

HashiCorp Vault's implementation of Shamir's secret sharing used precomputed table lookups, and was vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in Vault 1.13.1, 1.12.5, and 1.11.9.

CVSS 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-203, CWE-208
Also known as
BIT-vault-2023-25000, CVE-2023-25000, GO-2023-1709

More vault advisories

All
DateAdvisory
Mar 302023HashiCorp Vault's PKI mount vulnerable to denial of service
CVE-2023-0665Medium6.5fixed in 1.11.9, 1.12.5, 1.13.1
Mar 302023HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File
CVE-2023-0620Medium6.7fixed in 1.11.9, 1.12.5, 1.13.1
Jun 92023Hashicorp Vault vulnerable to Cross-site Scripting
CVE-2023-2121Medium4.3fixed in 1.11.11, 1.12.7, 1.13.3
Jul 62023HashiCorp Vault's revocation list not respected
CVE-2022-41316Medium5.3fixed in 1.9.10, 1.10.7, 1.11.4
Jul 62023Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation
CVE-2023-24999High8.1fixed in 1.10.11, 1.11.8, 1.12.4
Aug 12023HashiCorp Vault and Vault Enterprise vulnerable to user enumeration
CVE-2023-3462Medium5.3fixed in 1.13.5, 1.14.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.