Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8r5m-3f66-qpr3

Опубликовано: 17 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS

Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to these requests being sent to local network targets, potentially leading to information disclosure. Fixed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

Пакеты

Наименование

github.com/hashicorp/vault

go
Затронутые версииВерсия исправления

>= 1.14.0, <= 1.21.4

Отсутствует

EPSS

Процентиль: 26%
0.00332
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 5.8
redhat
4 месяца назад

Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to these requests being sent to local network targets, potentially leading to information disclosure. Fixed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

CVSS3: 5.3
nvd
4 месяца назад

Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to these requests being sent to local network targets, potentially leading to information disclosure. Fixed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

CVSS3: 8.6
fstec
4 месяца назад

Уязвимость механизма PKI Vault платформ для архивирования корпоративной информации HashiCorp Vault Community Edition и Vault Enterprise, позволяющая нарушителю раскрыть конфиденциальную информацию

CVSS3: 8.6
redos
2 месяца назад

Уязвимость vault

EPSS

Процентиль: 26%
0.00332
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-918