Loading HuntDB...

GHSA-hwc3-3qh6-r4gg

GitHub Security Advisory

HashiCorp Vault's PKI mount vulnerable to denial of service

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

HashiCorp Vault's PKI mount issuer endpoints did not correctly authorize access to remove an issuer or modify issuer metadata, potentially resulting in denial of service of the PKI mount. This bug did not affect public or private key material, trust chains or certificate issuance. Fixed in Vault 1.13.1, 1.12.5, and 1.11.9.

Affected Packages

Go github.com/hashicorp/vault
Affected versions: 0 (fixed in 1.11.9)
Go github.com/hashicorp/vault
Affected versions: 1.12.0 (fixed in 1.12.5)
Go github.com/hashicorp/vault
Affected versions: 1.13.0 (fixed in 1.13.1)

Related CVEs

Key Information

GHSA ID
GHSA-hwc3-3qh6-r4gg
Published
March 30, 2023 3:30 AM
Last Modified
April 7, 2023 7:22 PM
CVSS Score
5.0 /10
Primary Ecosystem
Go
Primary Package
github.com/hashicorp/vault
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 6, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.