HashiCorp Vault and Vault Enterprise vulnerable to user enumeration
Moderate severity
GitHub Reviewed
Published
Aug 1, 2023
to the GitHub Advisory Database
•
Updated Nov 11, 2023
Package
Affected versions
< 1.13.5
= 1.14.0
Patched versions
1.13.5
1.14.1
Description
Published by the National Vulnerability Database
Jul 31, 2023
Published to the GitHub Advisory Database
Aug 1, 2023
Reviewed
Aug 1, 2023
Last updated
Nov 11, 2023
HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existent and non-existent LDAP users and observe the response from Vault to check if the account is valid on the LDAP server. This vulnerability is fixed in Vault 1.14.1 and 1.13.5.
References