Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-45042

Опубликовано: 13 дек. 2021
Источник: redhat
CVSS3: 4.9
EPSS Низкий

Описание

In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.

A denial of service attack was discovered against vault. For clusters using the Integrated Storage (Raft) backend, an authenticated user with write permissions to the KV secrets engine can cause a panic leading to a denial of service of the storage backend, by supplying a key larger than 32KB.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-loki-rhel9Not affected
Red Hat Advanced Cluster Management for Kubernetes 2hashicorp/vaultNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-installerNot affected
Red Hat OpenShift Container Platform 4openshift4/topology-aware-lifecycle-manager-rhel8-operatorNot affected
Red Hat Openshift Container Storage 4ocs4/cephcsi-rhel8Not affected
Red Hat Openshift Container Storage 4ocs4/mcg-rhel8-operatorNot affected
Red Hat Openshift Container Storage 4ocs4/ocs-rhel8-operatorNot affected
Red Hat Openshift Container Storage 4ocs4/rook-ceph-rhel8-operatorNot affected
Red Hat Openshift Data Foundation 4mcgNot affected
Red Hat Openshift Data Foundation 4noobaa-operator-containerNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2034914vault: clusters using the integrated storage backend allowed an authenticated user to cause a DoS of the storage backend

EPSS

Процентиль: 71%
0.01407
Низкий

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
nvd
больше 4 лет назад

In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.

CVSS3: 4.9
github
больше 4 лет назад

In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.

EPSS

Процентиль: 71%
0.01407
Низкий

4.9 Medium

CVSS3