HashiCorp Vault and Vault Enterprise inbound client requests triggering a policy check can lead to an unbounded consumption of memory. A large number of these requests may lead to denial-of-service. Fixed in Vault 1.15.2, 1.14.6, and 1.13.10.
The product does not sufficiently track and release allocated memory after it has been used, which slowly consumes remaining memory.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vault | Hashicorp | 1.13.7 (including) | 1.13.10 (excluding) |
Vault | Hashicorp | 1.14.3 (including) | 1.14.6 (excluding) |
Vault | Hashicorp | 1.15.0 (including) | 1.15.2 (excluding) |
Red Hat OpenShift Container Platform 4.17 | RedHat | openshift4/ose-installer-rhel9:v4.17.0-202409122204.p0.gdfd4c08.assembly.stream.el9 | * |
RHODF-4.15-RHEL-9 | RedHat | odf4/mcg-rhel9-operator:v4.15.0-39 | * |