PT-2025-31679 · Hashicorp+2 · Vault Enterprise+3
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Vault versions prior to 1.20.1
Vault Enterprise versions prior to 1.20.1
Vault Enterprise version 1.19.7
Vault Enterprise version 1.18.12
Vault Enterprise version 1.16.23
Description
A timing side channel in the userpass authentication method allowed an attacker to differentiate between existing and non-existing users, potentially enabling the enumeration of valid usernames.
Recommendations
Update Vault to version 1.20.1 or later.
Update Vault Enterprise to version 1.20.1 or later.
Update Vault Enterprise to version 1.19.7 or later.
Update Vault Enterprise to version 1.18.12 or later.
Update Vault Enterprise to version 1.16.23 or later.
Exploit
Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Red Os
Vault
Vault Enterprise