CVE-2023-0665: Vault PKI Issuer Endpoint Did Not Correctly Authorize Access to Issuer Metadata
A flaw was found in the Hashicorp vault. Vault’s PKI mount issuer endpoints did not correctly authorize access to remove an issuer or modify issuer metadata, potentially resulting in a denial of service of the PKI mount. This bug did not affect public or private key material, trust chains, or certificate issuance.
Other sources
HashiCorp Vault's PKI mount issuer endpoints did not correctly authorize access to remove an issuer or modify issuer metadata, potentially resulting in denial of service of the PKI mount. This bug did not affect public or private key material, trust chains or certificate issuance. Fixed in Vault 1.13.1, 1.12.5, and 1.11.9.
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2023-0665?
CVE-2023-0665 is a vulnerability in HashiCorp Vault's PKI mount issuer endpoints that can result in denial of service of the PKI mount.
How does CVE-2023-0665 affect HashiCorp Vault?
CVE-2023-0665 affects HashiCorp Vault's PKI mount issuer endpoints, potentially resulting in denial of service of the PKI mount.
What is the severity of CVE-2023-0665?
CVE-2023-0665 has a severity rating of 6.5 out of 10, which is considered medium.
How do I fix CVE-2023-0665 in HashiCorp Vault?
To fix CVE-2023-0665 in HashiCorp Vault, update to version 1.13.1, 1.12.5, or 1.11.9.
Where can I find more information about CVE-2023-0665?
You can find more information about CVE-2023-0665 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-0665), [HashiCorp Discuss](https://discuss.hashicorp.com/t/hcsec-2023-11-vault-s-pki-issuer-endpoint-did-not-correctly-authorize-access-to-issuer-metadata/52079/1), [NetApp Security Advisory](https://security.netapp.com/advisory/ntap-20230526-0008/).