HashiCorp Vault's PKI mount issuer endpoints did not correctly authorize access to remove an issuer or modify issuer metadata, potentially resulting in denial of service of the PKI mount. This bug did not affect public or private key material, trust chains or certificate issuance. Fixed in Vault 1.13.1, 1.12.5, and 1.11.9.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Feb 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2025-02-13T16:39:04.425Z
Reserved: 2023-02-03T21:24:59.629Z
Link: CVE-2023-0665

Updated: 2024-08-02T05:17:50.328Z

Status : Modified
Published: 2023-03-30T01:15:07.437
Modified: 2024-11-21T07:37:35.217
Link: CVE-2023-0665
