CVE-2024-8185
HIGHHashiCorp Vault 1.2.0-1.18.0 and OpenBAO < 2.0.3 - Denial of Service via Raft Cluster Join API Endpoint
Title source: llmDescription
Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a denial-of-service (DoS) attack through memory exhaustion through a Raft cluster join API endpoint . An attacker may send a large volume of requests to the endpoint which may cause Vault to consume excessive system memory resources, potentially leading to a crash of the underlying system and the Vault process itself. This vulnerability, CVE-2024-8185, is fixed in Vault Community 1.18.1 and Vault Enterprise 1.18.1, 1.17.8, and 1.16.12.
References (1)
Core 1
Scores
CVSS v3
7.5
EPSS
0.0081
EPSS Percentile
74.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-636
Status
published
Products (6)
hashicorp/vault
1.18.0
hashicorp/vault
1.2.0 - 1.16.12
hashicorp/vault
1.2.0 - 1.18.1
hashicorp/vault
1.2.0 - 1.18.1Go
openbao/openbao
< 2.0.3
openbao/openbao
0 - 2.0.3Go
Published
Oct 31, 2024
Tracked Since
Feb 18, 2026