vaultGHSA-vq4h-9ghm-qmrr
HashiCorp Vault's implementation of Shamir's secret sharing vulnerable to cache-timing attacks
Medium4.7CVE-2023-25000 · Published Mar 30, 2023 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/vault Go | < 1.11.9 | 1.11.9 |
| >= 1.12.0, < 1.12.5 | 1.12.5 | |
| >= 1.13.0, < 1.13.1 | 1.13.1 |
Details and references
HashiCorp Vault's implementation of Shamir's secret sharing used precomputed table lookups, and was vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in Vault 1.13.1, 1.12.5, and 1.11.9.
More vault advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 302023 | HashiCorp Vault's PKI mount vulnerable to denial of service CVE-2023-0665Medium6.5fixed in 1.11.9, 1.12.5, 1.13.1 | Medium6.5 | 1.11.9, 1.12.5, 1.13.1 |
| Mar 302023 | HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File CVE-2023-0620Medium6.7fixed in 1.11.9, 1.12.5, 1.13.1 | Medium6.7 | 1.11.9, 1.12.5, 1.13.1 |
| Jun 92023 | Hashicorp Vault vulnerable to Cross-site Scripting CVE-2023-2121Medium4.3fixed in 1.11.11, 1.12.7, 1.13.3 | Medium4.3 | 1.11.11, 1.12.7, 1.13.3 |
| Jul 62023 | HashiCorp Vault's revocation list not respected CVE-2022-41316Medium5.3fixed in 1.9.10, 1.10.7, 1.11.4 | Medium5.3 | 1.9.10, 1.10.7, 1.11.4 |
| Jul 62023 | Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation CVE-2023-24999High8.1fixed in 1.10.11, 1.11.8, 1.12.4 | High8.1 | 1.10.11, 1.11.8, 1.12.4 |
| Aug 12023 | HashiCorp Vault and Vault Enterprise vulnerable to user enumeration CVE-2023-3462Medium5.3fixed in 1.13.5, 1.14.1 | Medium5.3 | 1.13.5, 1.14.1 |