id: GO-2023-2063 | |
modules: | |
- module: github.com/hashicorp/vault | |
versions: | |
- introduced: 1.6.0 | |
- fixed: 1.12.11 | |
- introduced: 1.13.0 | |
- fixed: 1.13.7 | |
- introduced: 1.14.0 | |
- fixed: 1.14.3 | |
vulnerable_at: 1.14.2 | |
summary: HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault | |
cves: | |
- CVE-2023-4680 | |
ghsas: | |
- GHSA-v84f-6r39-cpfc | |
references: | |
- advisory: https://github.com/advisories/GHSA-v84f-6r39-cpfc | |
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2023-4680 | |
- web: https://discuss.hashicorp.com/t/hcsec-2023-28-vault-s-transit-secrets-engine-allowed-nonce-specified-without-convergent-encryption/58249 | |
source: | |
id: GHSA-v84f-6r39-cpfc | |
created: 2024-08-20T12:02:57.129048-04:00 | |
review_status: UNREVIEWED | |
unexcluded: EFFECTIVELY_PRIVATE |