CVE-2023-6337
HashiCorp Vault and Vault Enterprise 1.12.0 and newer are vulnerable to a denial of service through memory exhaustion of the host when handling large unauthenticated and authenticated HTTP requests from a client. Vault will attempt to map the request to memory, resulting in the exhaustion of available memory on the host, which may cause Vault to crash. Fixed in Vault 1.15.4, 1.14.8, 1.13.12.
- Affected products
- Alt Linux, Hashicorp Vault, Red Os, Vault Enterprise
- Hashicorp Vault
- ≤ 1.12.0, 1.13.12, 1.14.8, 1.15.4
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 0.8% (53th percentile)
- Weakness
- CWE-770
- NVD status
- Modified
- Published
- 2023-12-08
- Attack patterns
- CAPEC-130
CVE-2023-6337 at NVD
No indexed exploits for CVE-2023-6337 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2023-6337 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.