First published: Fri Jul 28 2023(Updated: )
An unhandled error in Vault Enterprise's namespace creation may cause the Vault process to crash, potentially resulting in denial of service. Fixed in 1.14.1, 1.13.5, and 1.12.9.
Credit: security@hashicorp.com security@hashicorp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Vault | =1.12.8 | |
HashiCorp Vault | =1.13.4 | |
HashiCorp Vault | =1.14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3774 is an unhandled error in Vault Enterprise's namespace creation that may cause the Vault process to crash, potentially resulting in denial of service.
CVE-2023-3774 has a severity level of medium (4.9).
CVE-2023-3774 affects HashiCorp Vault versions 1.12.8, 1.13.4, and 1.14.0 in their enterprise editions.
You can mitigate CVE-2023-3774 by upgrading to Vault versions 1.14.1, 1.13.5, or 1.12.9, where the vulnerability is fixed.
More information about CVE-2023-3774 can be found at the following link: https://discuss.hashicorp.com/t/hcsec-2023-23-vault-enterprise-namespace-creation-may-lead-to-denial-of-service/56617