PT-2024-7644 · Hashicorp+3 · Vault Community+4

Published

2024-10-31

·

Updated

2025-11-13

·

CVE-2024-8185

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Vault Community versions prior to 1.18.1 Vault Enterprise versions prior to 1.18.1, 1.17.8, and 1.16.12
Description The issue is related to the Raft Consensus Algorithm in the Integrated Storage of HashiCorp Vault and Vault Enterprise, which can lead to unlimited resource consumption due to incorrect node joining in the cluster. This can be exploited by a remote attacker to cause a denial-of-service (DoS) through memory exhaustion. An attacker may send a large volume of requests to the Raft cluster join API endpoint, causing Vault to consume excessive system memory resources, potentially leading to a crash of the underlying system and the Vault process itself.
Recommendations For Vault Community versions prior to 1.18.1, update to version 1.18.1 or later. For Vault Enterprise versions prior to 1.18.1, update to version 1.18.1 or later. For Vault Enterprise versions prior to 1.17.8, update to version 1.17.8 or later. For Vault Enterprise versions prior to 1.16.12, update to version 1.16.12 or later. As a temporary workaround, consider restricting access to the Raft cluster join API endpoint to minimize the risk of exploitation.

Fix

DoS

Weakness Enumeration

Related Identifiers

ALT-PU-2024-17120
ALT-PU-2024-17177
ALT-PU-2024-17272
ALT-PU-2024-17791
BDU:2024-09085
BIT-VAULT-2024-8185
CVE-2024-8185
GHSA-G233-2P4R-3Q7V
GO-2024-3246
OPENSUSE-SU-2024:0350-1
OPENSUSE-SU-2024:14452-1
OPENSUSE-SU-2024_3950-1
SUSE-SU-2024:3950-1

Affected Products

Alt Linux
Red Os
Suse
Vault Community
Vault Enterprise