Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-3605

Опубликовано: 17 апр. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized to read or write, resulting in denial-of-service. This vulnerability did not allow a malicious user to delete secrets across namespaces, nor read any secret data. Fxed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

A flaw was found in Vault. An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized to read or write. This vulnerability can lead to a denial-of-service by allowing the deletion of critical data. It does not permit a malicious user to delete secrets across namespaces or read any secret data.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift4/ose-baremetal-installer-rhel9Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-installer-rhel9Not affected
Red Hat Openshift Data Foundation 4cephcsi-rhel8Not affected
Red Hat Openshift Data Foundation 4cephcsi-rhel9Not affected
Red Hat Openshift Data Foundation 4mcg-cli-rhel9Affected
Red Hat Openshift Data Foundation 4mcg-rhel8-operatorAffected
Red Hat Openshift Data Foundation 4mcg-rhel9-operatorAffected
Red Hat Openshift Data Foundation 4ocs4/cephcsi-rhel8Not affected
Red Hat Openshift Data Foundation 4odf4/cephcsi-rhel8Not affected
Red Hat Openshift Data Foundation 4odf4/cephcsi-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2459105Vault: Vault: Denial of Service due to unauthorized secret deletion via policy bypass

EPSS

Процентиль: 30%
0.00376
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
4 месяца назад

An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized to read or write, resulting in denial-of-service. This vulnerability did not allow a malicious user to delete secrets across namespaces, nor read any secret data. Fxed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

CVSS3: 8.1
github
4 месяца назад

HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service

CVSS3: 8.1
fstec
4 месяца назад

Уязвимость платформ для архивирования корпоративной информации HashiCorp Vault Community Edition и Vault Enterprise, связанная с обходом аутентификации посредством использования альтернативного пути или канала, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.1
redos
2 месяца назад

Уязвимость vault

EPSS

Процентиль: 30%
0.00376
Низкий

8.1 High

CVSS3