Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-4525

Опубликовано: 17 апр. 2026
Источник: redhat
CVSS3: 7.5

Описание

If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

A flaw was found in Vault. When a Vault authentication mount is configured to pass through the "Authorization" header, and this header is used for authentication, Vault incorrectly forwards the sensitive Vault token to the authentication plugin backend. This can lead to the disclosure of authentication tokens to potentially untrusted or compromised backend plugins, enabling unauthorized access or further system compromise.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift4/ose-baremetal-installer-rhel9Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-installer-rhel9Not affected
Red Hat Openshift Data Foundation 4cephcsi-rhel8Not affected
Red Hat Openshift Data Foundation 4cephcsi-rhel9Not affected
Red Hat Openshift Data Foundation 4mcg-cli-rhel9Affected
Red Hat Openshift Data Foundation 4mcg-rhel8-operatorAffected
Red Hat Openshift Data Foundation 4mcg-rhel9-operatorAffected
Red Hat Openshift Data Foundation 4ocs4/cephcsi-rhel8Not affected
Red Hat Openshift Data Foundation 4odf4/cephcsi-rhel8Not affected
Red Hat Openshift Data Foundation 4odf4/cephcsi-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=2459107Vault: Vault: Information disclosure of authentication tokens via incorrect header handling

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
4 месяца назад

If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

CVSS3: 7.5
github
4 месяца назад

HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость платформ для архивирования корпоративной информации HashiCorp Vault Community Edition и Vault Enterprise, связанная с раскрытием информации при передаче данных, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.5
redos
2 месяца назад

Уязвимость vault

7.5 High

CVSS3