VDB

CVE-2023-3462

CVE-2023-3462 PUBLISHED CVSS 5.300000190734863 MEDIUM

HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existent and non-existent LDAP users and observe the response from Vault to check if the account is valid on the LDAP server. This vulnerability is fixed in Vault 1.14.1 and 1.13.5.

EPSS 0.61% · 47.5th percentile

Risk Scores

CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.61%
47.5th percentile

Affected Products

VendorProductVersions
Bitnamivault1.13.0, 1.14.0
Bitnamivault1.13.0, 1.14.0

Timeline

  • Jul 31, 2023 CVE Published
  • Aug 1, 2023 CVE Updated
  • Aug 1, 2023 EPSS Score
  • Sep 5, 2023 EPSS Score
  • Oct 9, 2023 EPSS Score
  • Dec 17, 2023 EPSS Score
  • Jan 21, 2024 EPSS Score
  • Feb 24, 2024 EPSS Score
  • Mar 30, 2024 EPSS Score
  • May 3, 2024 EPSS Score
  • Jun 7, 2024 EPSS Score
  • Aug 15, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›