HashiCorp Vault Enterprise 1.13.0 up to 1.13.1 is...
Unreviewed
Published
Jul 6, 2023
to the GitHub Advisory Database
•
Updated Nov 10, 2023
Description
Published by the National Vulnerability Database
May 1, 2023
Published to the GitHub Advisory Database
Jul 6, 2023
Last updated
Nov 10, 2023
HashiCorp Vault Enterprise 1.13.0 up to 1.13.1 is vulnerable to a padding oracle attack when using an HSM in conjunction with the CKM_AES_CBC_PAD or CKM_AES_CBC encryption mechanisms. An attacker with privileges to modify storage and restart Vault may be able to intercept or modify cipher text in order to derive Vault’s root key. Fixed in 1.13.2
References