Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-45042

Опубликовано: 17 дек. 2021
Источник: nvd
CVSS3: 4.9
CVSS2: 6.8
EPSS Низкий

Описание

In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*
Версия от 1.4.0 (включая) до 1.7.7 (исключая)
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*
Версия от 1.4.0 (включая) до 1.7.7 (исключая)
cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*
Версия от 1.8.0 (включая) до 1.8.6 (исключая)
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*
Версия от 1.8.0 (включая) до 1.8.6 (исключая)
cpe:2.3:a:hashicorp:vault:1.9.0:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:vault:1.9.0:*:*:*:enterprise:*:*:*

EPSS

Процентиль: 62%
0.00435
Низкий

4.9 Medium

CVSS3

6.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 4.9
redhat
около 4 лет назад

In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.

CVSS3: 4.9
github
около 4 лет назад

In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.

EPSS

Процентиль: 62%
0.00435
Низкий

4.9 Medium

CVSS3

6.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo