Описание
Vault and Vault Enterprise TLS certificates auth method did not correctly validate OCSP responses when one or more OCSP sources were configured. This vulnerability, CVE-2024-2660, affects Vault and Vault Enterprise 1.14.0 and above, and is fixed in Vault 1.16.0 and Vault Enterprise 1.16.1, 1.15.7, and 1.14.11.
A flaw was found in the OCSP response handling logic of Vault’s TLS certificate authentication method. This issue may result in signatures and responses from multiple servers not being handled properly. A malicious actor with privileged network access may be able to successfully authenticate via Vault’s TLS certificate authentication method with incorrect certificate status information.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Openshift Container Storage 4 | ocs4/cephcsi-rhel8 | Not affected | ||
Red Hat Openshift Container Storage 4 | ocs4/mcg-rhel8-operator | Not affected | ||
Red Hat Openshift Container Storage 4 | ocs4/ocs-rhel8-operator | Not affected | ||
Red Hat Openshift Container Storage 4 | ocs4/rook-ceph-rhel8-operator | Not affected | ||
Red Hat Openshift Data Foundation 4 | odf4/cephcsi-rhel9 | Not affected | ||
Red Hat Openshift Data Foundation 4 | odf4/mcg-cli-rhel9 | Not affected | ||
Red Hat Openshift Data Foundation 4 | odf4/mcg-rhel9-operator | Not affected | ||
Red Hat Openshift Data Foundation 4 | odf4/ocs-rhel9-operator | Not affected | ||
Red Hat Openshift Data Foundation 4 | odf4/odf-cli-rhel9 | Not affected | ||
Red Hat Openshift Data Foundation 4 | odf4/odf-multicluster-rhel9-operator | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.4 Medium
CVSS3
Связанные уязвимости
Vault and Vault Enterprise TLS certificates auth method did not correctly validate OCSP responses when one or more OCSP sources were configured. This vulnerability, CVE-2024-2660, affects Vault and Vault Enterprise 1.14.0 and above, and is fixed in Vault 1.16.0 and Vault Enterprise 1.16.1, 1.15.7, and 1.14.11.
HashiCorpVault does not correctly validate OCSP responses
Уязвимость компонента проверки сертификатов TLS платформ для архивирования корпоративной информации HashiCorp Vault и Vault Enterprise, позволяющая нарушителю обойти процесс аутентификации
EPSS
6.4 Medium
CVSS3