Vulnerabilities
Vulnerable Software
Hashicorp:  >> Vault  >> 1.15.4  Security Vulnerabilities
Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In this configuration, an attacker may be able to craft a malicious certificate that could be used to bypass authentication. Fixed in Vault 1.15.5 and 1.14.10.
CVSS Score
8.1
EPSS Score
0.002
Published
2024-03-04
Vault and Vault Enterprise (“Vault”) may expose sensitive information when enabling an audit device which specifies the `log_raw` option, which may log sensitive information to other audit devices, regardless of whether they are configured to use `log_raw`.
CVSS Score
4.5
EPSS Score
0.002
Published
2024-02-01


Contact Us

Shodan ® - All rights reserved