Back

MEDIUM

Vault's Transit Secrets Engine Allowed Nonce Specified without Convergent Encryption

Published Sep 14, 2023

Description

HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even with convergent encryption disabled. The encrypt endpoint, in combination with an offline attack, could be used to decrypt arbitrary ciphertext and potentially derive the authentication subkey when using transit secrets engine without convergent encryption. Introduced in 1.6.0 and fixed in 1.14.3, 1.13.7, and 1.12.11.

Affected products

Remediation

No remediation recorded yet.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner HashiCorp
Published Sep 14, 2023
Updated Sep 26, 2024
Reserved Aug 31, 2023
CISA Vulnrichment
Updated Sep 25, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 6, 2023
ENISA EUVD
Assigner HashiCorp
Published Sep 14, 2023
Updated Sep 26, 2024
Exploited since n/a
EUVD-2023-2597 GHSA-V84F-6R39-CPFC