HashiCorp Vault's PKI mount issuer endpoints did not correctly authorize access to remove an issuer or modify issuer metadata, potentially resulting in denial of service of the PKI mount. This bug did not affect public or private key material, trust chains or certificate issuance. Fixed in Vault 1.13.1, 1.12.5, and 1.11.9.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 07:37
Type | Values Removed | Values Added |
---|---|---|
References | () https://discuss.hashicorp.com/t/hcsec-2023-11-vault-s-pki-issuer-endpoint-did-not-correctly-authorize-access-to-issuer-metadata/52079/1 - Issue Tracking, Patch, Vendor Advisory | |
References | () https://security.netapp.com/advisory/ntap-20230526-0008/ - |
26 May 2023, 20:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2023-03-30 01:15
Updated : 2024-11-21 07:37
NVD link : CVE-2023-0665
Mitre link : CVE-2023-0665
CVE.ORG link : CVE-2023-0665
JSON object : View
Products Affected
hashicorp
- vault
CWE