CVE-2023-3462 PUBLISHED

HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existent and non-existent LDAP users and observe the response from Vault to check if the account is valid on the LDAP server. This vulnerability is fixed in Vault 1.14.1 and 1.13.5.

EPSS 1.01% · 76.9th percentile

Risk Scores

EPSS Score
1.01%
76.9th percentile

Affected Products

VendorProductVersions
Bitnamivault1.13.0, 1.14.0
Bitnamivault1.13.0, 1.14.0

Timeline

References

Open in Interactive Console →