Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:44239
HistoryNov 13, 2023 - 6:51 a.m.

Denial Of Service (DoS)

2023-11-1306:51:11
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
memory leak
malicious requests
vulnerability
github
vault
denial-of-service
software

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

17.0%

github.com/hashicorp/vault is vulnerable to Denial of Service (DoS). A memory leak vulnerability allows an attacker to cause a denial-of-service (DoS) attacks against a vulnerable Vault instance by sending a large number of malicious client requests. The malicious requests would cause Vault to consume all of the available memory and cause Vault to crash.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

17.0%