Wiz Agents & Workflows are here

CVE-2023-25000
HashiCorp Vault vulnerability analysis and mitigation

Overview

HashiCorp Vault's implementation of Shamir's secret sharing was found to be vulnerable to cache-timing attacks, identified as CVE-2023-25000. The vulnerability was discovered and disclosed on March 29, 2023, affecting Vault and Vault Enterprise versions up to 1.13.0, 1.12.4, and 1.11.8. The issue has been fixed in versions 1.13.1, 1.12.5, and 1.11.9 (HashiCorp Discuss).

Technical details

The vulnerability stems from Vault's Shamir implementation using Go's crypto/subtle package and constant time functions. The specific issue lies in the mult and div operations that compute differences between precomputed Galois Field log tables. When these tables are loaded into the CPU cache, the loading pattern creates cache-timing leaks. The vulnerability has been assigned a CVSS v3.1 base score of 4.7 (MEDIUM) with the vector string CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N (NetApp Security).

Impact

An attacker with access to and the ability to observe a large number of unseal operations on the host through a side channel could potentially reduce the search space of a brute force effort to recover the Shamir shares. If successful, this could result in the retrieval of sensitive data, such as the unseal or root key (HashiCorp Discuss).

Mitigation and workarounds

The recommended mitigation is to upgrade to Vault Enterprise versions 1.13.1, 1.12.5, 1.11.9, or newer. The mult and div functions used in Vault's Shamir implementation have been modified to remove table lookups and negate this attack vector. Organizations should evaluate their risk exposure and follow the general guidance provided in Vault's upgrading documentation (HashiCorp Discuss).

Additional resources


SourceThis report was generated using AI

Related HashiCorp Vault vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-33186CRITICAL9.1
  • cAdvisorcAdvisor
  • crossplane-provider-terraform-fips
NoYesMar 20, 2026
CVE-2026-27137HIGH7.5
  • GrafanaGrafana
  • weaviate-1.32
NoYesMar 06, 2026
CVE-2026-27142MEDIUM6.1
  • cAdvisorcAdvisor
  • cluster-api-aws-controller-fips
NoYesMar 06, 2026
CVE-2026-27138MEDIUM5.9
  • HashiCorp VaultHashiCorp Vault
  • cluster-autoscaler-fips-1.35
NoYesMar 06, 2026
CVE-2026-27139LOW2.5
  • cAdvisorcAdvisor
  • terraform-provider-aws-fips
NoYesMar 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management