Loading HuntDB...

GHSA-v84f-6r39-cpfc

GitHub Security Advisory

HashiCorp Vault Improper Input Validation vulnerability

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even with convergent encryption disabled. The encrypt endpoint, in combination with an offline attack, could be used to decrypt arbitrary ciphertext and potentially derive the authentication subkey when using transit secrets engine without convergent encryption. Introduced in 1.6.0 and fixed in 1.14.3, 1.13.7, and 1.12.11.

Affected Packages

Go github.com/hashicorp/vault
Affected versions: 1.6.0 (fixed in 1.12.11)
Go github.com/hashicorp/vault
Affected versions: 1.13.0 (fixed in 1.13.7)
Go github.com/hashicorp/vault
Affected versions: 1.14.0 (fixed in 1.14.3)

Related CVEs

Key Information

GHSA ID
GHSA-v84f-6r39-cpfc
Published
September 15, 2023 12:30 AM
Last Modified
September 15, 2023 7:03 PM
CVSS Score
5.0 /10
Primary Ecosystem
Go
Primary Package
github.com/hashicorp/vault
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 6, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.