| id: GO-2023-1685 | 
 | modules: | 
 |     - module: github.com/hashicorp/vault | 
 |       versions: | 
 |         - introduced: 0.8.0 | 
 |         - fixed: 1.11.9 | 
 |         - introduced: 1.12.0 | 
 |         - fixed: 1.12.5 | 
 |         - introduced: 1.13.0 | 
 |         - fixed: 1.13.1 | 
 |       vulnerable_at: 1.13.0 | 
 | summary: |- | 
 |     HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL | 
 |     Injection Via Configuration File in github.com/hashicorp/vault | 
 | cves: | 
 |     - CVE-2023-0620 | 
 | ghsas: | 
 |     - GHSA-v3hp-mcj5-pg39 | 
 | references: | 
 |     - advisory: https://github.com/advisories/GHSA-v3hp-mcj5-pg39 | 
 |     - advisory: https://nvd.nist.gov/vuln/detail/CVE-2023-0620 | 
 |     - fix: https://github.com/hashicorp/vault/pull/19591 | 
 |     - web: https://discuss.hashicorp.com/t/hcsec-2023-12-vault-s-microsoft-sql-database-storage-backend-vulnerable-to-sql-injection-via-configuration-file/52080/1 | 
 |     - web: https://github.com/hashicorp/vault/releases/tag/v1.11.9 | 
 |     - web: https://github.com/hashicorp/vault/releases/tag/v1.12.5 | 
 |     - web: https://github.com/hashicorp/vault/releases/tag/v1.13.1 | 
 |     - web: https://security.netapp.com/advisory/ntap-20230526-0008 | 
 | source: | 
 |     id: GHSA-v3hp-mcj5-pg39 | 
 |     created: 2024-08-20T11:39:32.133068-04:00 | 
 | review_status: UNREVIEWED | 
 | unexcluded: EFFECTIVELY_PRIVATE |