VDB

CVE-2023-3462

CVE-2023-3462 PUBLISHED

HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existent and non-existent LDAP users and observe the response from Vault to check if the account is valid on the LDAP server. This vulnerability is fixed in Vault 1.14.1 and 1.13.5.

EPSS 0.98% · 77.1th percentile

Risk Scores

EPSS Score
0.98%
77.1th percentile

Affected Products

VendorProductVersions
Bitnamivault1.13.0, 1.14.0
Bitnamivault1.13.0, 1.14.0

Timeline

  • Jul 31, 2023 CVE Published
  • Aug 1, 2023 EPSS Score
  • Sep 4, 2023 EPSS Score
  • Oct 8, 2023 EPSS Score
  • Dec 15, 2023 EPSS Score
  • Jan 17, 2024 EPSS Score
  • Feb 20, 2024 EPSS Score
  • Mar 25, 2024 EPSS Score
  • Apr 28, 2024 EPSS Score
  • Jun 1, 2024 EPSS Score
  • Aug 8, 2024 EPSS Score
  • Sep 11, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›