PT-2023-19855 · Hashicorp+1 · Hashicorp Vault+1
Giuseppe Cocomazzi
·
Publicado
2023-03-29
·
Atualizado
2025-05-26
·
CVE-2023-25000
CVSS v3.1
5.0
Média
| Vetor | AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HashiCorp Vault versions prior to 1.11.9
HashiCorp Vault versions prior to 1.12.5
HashiCorp Vault versions prior to 1.13.1
Description
The issue concerns HashiCorp Vault's implementation of Shamir's secret sharing, which used precomputed table lookups and was vulnerable to cache-timing attacks. An attacker with access to the host and the ability to observe a large number of unseal operations through a side channel may reduce the search space of a brute force effort to recover the Shamir shares.
Recommendations
For versions prior to 1.11.9, update to version 1.11.9 or later.
For versions prior to 1.12.5, update to version 1.12.5 or later.
For versions prior to 1.13.1, update to version 1.13.1 or later.
Correção
Side Channel Attack
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Hashicorp Vault
Red Os