{ "schema_version": "1.3.1", "id": "GO-2023-1708", "modified": "0001-01-01T00:00:00Z", "published": "0001-01-01T00:00:00Z", "aliases": [ "CVE-2023-0665", "GHSA-hwc3-3qh6-r4gg" ], "summary": "HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault", "details": "HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault", "affected": [ { "package": { "name": "github.com/hashicorp/vault", "ecosystem": "Go" }, "ranges": [ { "type": "SEMVER", "events": [ { "introduced": "0" }, { "fixed": "1.11.9" }, { "introduced": "1.12.0" }, { "fixed": "1.12.5" }, { "introduced": "1.13.0" }, { "fixed": "1.13.1" } ] } ], "ecosystem_specific": {} } ], "references": [ { "type": "ADVISORY", "url": "https://github.com/advisories/GHSA-hwc3-3qh6-r4gg" }, { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0665" }, { "type": "WEB", "url": "https://discuss.hashicorp.com/t/hcsec-2023-11-vault-s-pki-issuer-endpoint-did-not-correctly-authorize-access-to-issuer-metadata/52079/1" }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20230526-0008" } ], "database_specific": { "url": "https://pkg.go.dev/vuln/GO-2023-1708", "review_status": "UNREVIEWED" } }