Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a denial-of-service (DoS) attack through memory exhaustion through a Raft cluster join API endpoint . An attacker may send a large volume of requests to the endpoint which may cause Vault to consume excessive system memory resources, potentially leading to a crash of the underlying system and the Vault process itself.
This vulnerability, CVE-2024-8185, is fixed in Vault Community 1.18.1 and Vault Enterprise 1.18.1, 1.17.8, and 1.16.12.
{
"cwe_ids": [
"CWE-636"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/8xxx/CVE-2024-8185.json",
"cna_assigner": "HashiCorp"
}{
"cpe": [
"cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*",
"cpe:2.3:a:hashicorp:vault:1.18.0:*:*:*:enterprise:*:*:*"
],
"extracted_events": [
{
"introduced": "1.2.0"
},
{
"fixed": "1.18.1"
},
{
"introduced": "1.18.0"
},
{
"last_affected": "1.18.0"
}
],
"source": [
"CPE_RANGE",
"CPE_STRING"
]
}
{
"cpe": "cpe:2.3:a:openbao:openbao:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.0.3"
}
],
"source": "CPE_RANGE"
}