CVE-2023-3462
Vault's LDAP Auth Method Allows for User Enumeration
5.3
MEDIUM
CVSS 3.1
EPSS 0.61%
描述
HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existent and non-existent LDAP users and observe the response from Vault to check if the account is valid on the LDAP server. This vulnerability is fixed in Vault 1.14.1 and 1.13.5.
如何修補 CVE-2023-3462
要修補 CVE-2023-3462,請將受影響套件升級到下列已修補版本。
- —升級至 1.13.5 或更新版本
- —升級至 1.13.5 或更新版本
- —升級至 1.13.5 或更新版本
CVE-2023-3462 正在被利用嗎?
低 — EPSS 為 0.6%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- >= 1.13.0, < 1.13.5, >= 1.14.0, < 1.14.1
- from 0, < 1.13.5
- from 0, < 1.13.5, >= 1.14.0, < 1.14.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |