GHSA-v84f-6r39-cpfc
GitHub Security Advisory
HashiCorp Vault Improper Input Validation vulnerability
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even with convergent encryption disabled. The encrypt endpoint, in combination with an offline attack, could be used to decrypt arbitrary ciphertext and potentially derive the authentication subkey when using transit secrets engine without convergent encryption. Introduced in 1.6.0 and fixed in 1.14.3, 1.13.7, and 1.12.11.
Affected Packages
Go
github.com/hashicorp/vault
Affected versions:
1.6.0
(fixed in 1.12.11)
Go
github.com/hashicorp/vault
Affected versions:
1.13.0
(fixed in 1.13.7)
Go
github.com/hashicorp/vault
Affected versions:
1.14.0
(fixed in 1.14.3)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 6, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.