Vulnerability Details CVE-2022-25243
"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates to authorized users for a specified domain, even if the PKI role policy attribute allow_subdomains is set to false. Fixed in Vault Enterprise 1.8.9 and 1.9.4.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 37.7%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 3.5
Products affected by CVE-2022-25243
-
cpe:2.3:a:hashicorp:vault:1.8.0
-
cpe:2.3:a:hashicorp:vault:1.8.3
-
cpe:2.3:a:hashicorp:vault:1.8.4
-
cpe:2.3:a:hashicorp:vault:1.8.6
-
cpe:2.3:a:hashicorp:vault:1.8.7
-
cpe:2.3:a:hashicorp:vault:1.8.8
-
cpe:2.3:a:hashicorp:vault:1.9.0
-
cpe:2.3:a:hashicorp:vault:1.9.1
-
cpe:2.3:a:hashicorp:vault:1.9.2
-
cpe:2.3:a:hashicorp:vault:1.9.3