CVE-2023-3462

CVE-2023-3462

HashiCorp’s Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existent and non-existent LDAP users and observe the response from Vault to check if the account is valid on the LDAP server. This vulnerability is fixed in Vault 1.14.1 and 1.13.5.

Source: CVE-2023-3462

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다