CVE-2023-0665
HashiCorp Vault vulnerability analysis and mitigation

Overview

HashiCorp Vault's PKI mount issuer endpoints contained a vulnerability (CVE-2023-0665) that failed to properly authorize access to remove an issuer or modify issuer metadata. The vulnerability was introduced in Vault 1.11.0 and has been fixed in versions 1.13.1, 1.12.5, and 1.11.9. This security issue specifically affected the PKI mount functionality but did not impact public or private key material, trust chains, or certificate issuance (HashiCorp Discussion).

Technical details

The vulnerability affected a subset of issuer endpoints (/issuer/:ref/{json,der,pem}), while the primary /issuer/:ref endpoint remained properly authenticated. Several unauthenticated endpoints did not correctly authorize inbound requests, allowing modification or deletion of certain metadata fields. The issue was discovered during internal testing by the Vault engineering team (HashiCorp Discussion).

Impact

An attacker could potentially modify or delete authority information fields for existing issuers, including crl_distribution_points and oscp_server, which could result in a denial of service for the affected PKI mount. Any deleted issuer CA certificates could be safely re-imported as the integrity and availability of all key material and certificates remained unaffected (HashiCorp Discussion).

Mitigation and workarounds

Organizations should upgrade to Vault Enterprise versions 1.13.1, 1.12.5, 1.11.9, or newer to remediate this vulnerability. The Vault team maintains documentation and best practices for the PKI secrets engine that should be followed for secure implementation (HashiCorp Discussion).

Additional resources


SourceThis report was generated using AI

Related HashiCorp Vault vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-61729HIGH7.5
  • cAdvisorcAdvisor
  • rancher-fleet
NoYesDec 02, 2025
CVE-2025-63811HIGH7.5
  • HashiCorp VaultHashiCorp Vault
  • argo-events
NoYesNov 12, 2025
CVE-2025-61727MEDIUM6.5
  • cAdvisorcAdvisor
  • etcd-3.5
NoYesDec 03, 2025
CVE-2025-58181MEDIUM5.3
  • cAdvisorcAdvisor
  • bento
NoYesNov 19, 2025
CVE-2025-47914MEDIUM5.3
  • cAdvisorcAdvisor
  • external-secrets-operator-fips-0.17
NoYesNov 19, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management