VDB
Sign up
MEDIUM5.3

GHSA-9v3w-w2jh-4hff

HashiCorp Vault and Vault Enterprise vulnerable to user enumeration

Quick fix

GHSA-9v3w-w2jh-4hff — github.com/hashicorp/vault: upgrade to the fixed version with the command below.

go get github.com/hashicorp/vault@v1.13.5

Details

HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existent and non-existent LDAP users and observe the response from Vault to check if the account is valid on the LDAP server. This vulnerability is fixed in Vault 1.14.1 and 1.13.5.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/hashicorp/vault
Introduced in: 0Fixed in: 1.13.5
Fixgo get github.com/hashicorp/vault@v1.13.5
Go/github.com/hashicorp/vault
Introduced in: 1.14.0Fixed in: 1.14.1
Fixgo get github.com/hashicorp/vault@v1.14.1

References