Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Giuseppe Cocomazzi

#49338of 53,633
5Total CVSS
Vulnerabilities · 1
PT-2023-19855
5.0
2023-03-29
Hashicorp · Hashicorp Vault · CVE-2023-25000
**Name of the Vulnerable Software and Affected Versions** HashiCorp Vault versions prior to 1.11.9 HashiCorp Vault versions prior to 1.12.5 HashiCorp Vault versions prior to 1.13.1 **Description** The issue concerns HashiCorp Vault's implementation of Shamir's secret sharing, which used precomputed table lookups and was vulnerable to cache-timing attacks. An attacker with access to the host and the ability to observe a large number of unseal operations through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. **Recommendations** For versions prior to 1.11.9, update to version 1.11.9 or later. For versions prior to 1.12.5, update to version 1.12.5 or later. For versions prior to 1.13.1, update to version 1.13.1 or later.