Timing Attack Affecting github.com/hashicorp/vault/shamir package, versions <1.11.9>=1.12.0-rc1 <1.12.5>=1.13.0-rc1 <1.13.11


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.04% (15th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMHASHICORPVAULTSHAMIR-5296695
  • published30 Mar 2023
  • disclosed30 Mar 2023
  • creditUnknown

Introduced: 30 Mar 2023

CVE-2023-25000  (opens in a new tab)
CWE-208  (opens in a new tab)

How to fix?

Upgrade github.com/hashicorp/vault/shamir to version 1.11.9, 1.12.5, 1.13.11 or higher.

Overview

Affected versions of this package are vulnerable to Timing Attack. An attacker with access and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares.

CVSS Scores

version 3.1