Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-8185— Vault Vulnerable to Denial of Service When Processing Raft Join Requests

CVSS 7.5 · High EPSS 0.81% · P74
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-8185

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Vault Vulnerable to Denial of Service When Processing Raft Join Requests
Source: NVD (National Vulnerability Database)
Vulnerability Description
Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a denial-of-service (DoS) attack through memory exhaustion through a Raft cluster join API endpoint . An attacker may send a large volume of requests to the endpoint which may cause Vault to consume excessive system memory resources, potentially leading to a crash of the underlying system and the Vault process itself. This vulnerability, CVE-2024-8185, is fixed in Vault Community 1.18.1 and Vault Enterprise 1.18.1, 1.17.8, and 1.16.12.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
未能安全地进行程序失效(Failing Open)
Source: NVD (National Vulnerability Database)
Vulnerability Title
HashiCorp Vault 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
HashiCorp Vault是美国HashiCorp公司的一款私钥访问管理工具。 HashiCorp Vault存在安全漏洞,该漏洞源于容易拒绝服务(DoS)攻击,攻击者可能会向端点发送大量请求导致Vault消耗过多的系统内存资源,从而导致底层系统和Vault进程本身崩溃。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
HashiCorpVault 1.2.0 ~ 1.18.1 -
HashiCorpVault Enterprise 1.2.0 ~ 1.18.1 -

II. Public POCs for CVE-2024-8185

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-8185

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2024-8185

No comments yet


Leave a comment