VDB
CVE-2023-3462
CVE-2023-3462
PUBLISHED
HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existent and non-existent LDAP users and observe the response from Vault to check if the account is valid on the LDAP server. This vulnerability is fixed in Vault 1.14.1 and 1.13.5.
EPSS 0.61% · 46.1th percentile
Risk Scores
EPSS Score
0.61%
46.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | vault | 1.13.0, 1.14.0 |
| Bitnami | vault | 1.13.0, 1.14.0 |
Timeline
- Jul 31, 2023 CVE Published
- Aug 1, 2023 CVE Updated
- Aug 1, 2023 EPSS Score
- Sep 4, 2023 EPSS Score
- Oct 8, 2023 EPSS Score
- Dec 15, 2023 EPSS Score
- Jan 18, 2024 EPSS Score
- Feb 21, 2024 EPSS Score
- Mar 26, 2024 EPSS Score
- Apr 28, 2024 EPSS Score
- Jun 1, 2024 EPSS Score
- Aug 8, 2024 EPSS Score