CVE-2021-45042

Description

In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.

Risk Information

Base Score
4.9
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.435

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-45042 are affected in HashiCorp Vault Enterprise 1.7.6Windows
Vulnerabilities CVE-2021-45042 are affected in HashiCorp Vault Enterprise 1.8.5Windows
Vulnerabilities CVE-2021-45042 are affected in HashiCorp Vault Enterprise 1.9.0Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234