VDB
CVE-2023-3462
CVE-2023-3462
PUBLISHED
CVSS 5.300000190734863 MEDIUM
HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existent and non-existent LDAP users and observe the response from Vault to check if the account is valid on the LDAP server. This vulnerability is fixed in Vault 1.14.1 and 1.13.5.
EPSS 0.61% · 47.5th percentile
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.61%
47.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | vault | 1.13.0, 1.14.0 |
| Bitnami | vault | 1.13.0, 1.14.0 |
Timeline
- Jul 31, 2023 CVE Published
- Aug 1, 2023 CVE Updated
- Aug 1, 2023 EPSS Score
- Sep 5, 2023 EPSS Score
- Oct 9, 2023 EPSS Score
- Dec 17, 2023 EPSS Score
- Jan 21, 2024 EPSS Score
- Feb 24, 2024 EPSS Score
- Mar 30, 2024 EPSS Score
- May 3, 2024 EPSS Score
- Jun 7, 2024 EPSS Score
- Aug 15, 2024 EPSS Score