CVE-2023-5954

HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in go/github.com/hashicorp/vault

Identifiers

GHSA-4qhc-v8r6-8vwm, CVE-2023-5954

Package Slug

go/github.com/hashicorp/vault

Vulnerability

HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability

Description

HashiCorp Vault and Vault Enterprise inbound client requests triggering a policy check can lead to an unbounded consumption of memory. A large number of these requests may lead to denial-of-service. Fixed in Vault 1.15.2, 1.14.6, and 1.13.10.

Affected Versions

All versions before 1.13.10, all versions starting from 1.14.0 before 1.14.6, all versions starting from 1.15.0 before 1.15.2

Solution

Upgrade to versions 1.13.10, 1.14.6, 1.15.2 or above.

Last Modified

2023-11-10

source