Логотип exploitDog
bind: "CVE-2022-40186"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2022-40186"

Количество 5

Количество 5

redhat логотип

CVE-2022-40186

больше 2 лет назад

An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may allow for unintended access to key/value paths using that metadata in Vault.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2022-40186

больше 2 лет назад

An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may allow for unintended access to key/value paths using that metadata in Vault.

CVSS3: 9.1
EPSS: Низкий
redos логотип

ROS-20250402-08

3 месяца назад

Уязвимость vault

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-7cgv-v83v-rr87

больше 2 лет назад

HashiCorp Vault vulnerable to incorrect metadata access

CVSS3: 9.1
EPSS: Низкий
fstec логотип

BDU:2025-04009

больше 2 лет назад

Уязвимость платформ для архивирования корпоративной информации HashiCorp Vault и Vault Enterprise, связанная с недостатками разграничения доступа, позволяющая нарушителю получить доступ к потенциально конфиденциальной информации

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-40186

An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may allow for unintended access to key/value paths using that metadata in Vault.

CVSS3: 9.1
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2022-40186

An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may allow for unintended access to key/value paths using that metadata in Vault.

CVSS3: 9.1
0%
Низкий
больше 2 лет назад
redos логотип
ROS-20250402-08

Уязвимость vault

CVSS3: 9.1
0%
Низкий
3 месяца назад
github логотип
GHSA-7cgv-v83v-rr87

HashiCorp Vault vulnerable to incorrect metadata access

CVSS3: 9.1
0%
Низкий
больше 2 лет назад
fstec логотип
BDU:2025-04009

Уязвимость платформ для архивирования корпоративной информации HashiCorp Vault и Vault Enterprise, связанная с недостатками разграничения доступа, позволяющая нарушителю получить доступ к потенциально конфиденциальной информации

CVSS3: 9.1
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу