Количество 5
Количество 5

CVE-2024-2048
Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In this configuration, an attacker may be able to craft a malicious certificate that could be used to bypass authentication. Fixed in Vault 1.15.5 and 1.14.10.

CVE-2024-2048
Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In this configuration, an attacker may be able to craft a malicious certificate that could be used to bypass authentication. Fixed in Vault 1.15.5 and 1.14.10.
GHSA-r3w7-mfpm-c2vw
Incorrect TLS certificate auth method in Vault

BDU:2024-02063
Уязвимость платформ для архивирования корпоративной информации HashiCorp Vault и Vault Enterprise, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю обойти процесс аутентификации

ROS-20240805-04
Множественные уязвимости vault
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2024-2048 Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In this configuration, an attacker may be able to craft a malicious certificate that could be used to bypass authentication. Fixed in Vault 1.15.5 and 1.14.10. | CVSS3: 8.1 | 0% Низкий | больше 1 года назад |
![]() | CVE-2024-2048 Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In this configuration, an attacker may be able to craft a malicious certificate that could be used to bypass authentication. Fixed in Vault 1.15.5 and 1.14.10. | CVSS3: 8.1 | 0% Низкий | больше 1 года назад |
GHSA-r3w7-mfpm-c2vw Incorrect TLS certificate auth method in Vault | CVSS3: 8.1 | 0% Низкий | больше 1 года назад | |
![]() | BDU:2024-02063 Уязвимость платформ для архивирования корпоративной информации HashiCorp Vault и Vault Enterprise, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю обойти процесс аутентификации | CVSS3: 8.1 | 0% Низкий | больше 1 года назад |
![]() | ROS-20240805-04 Множественные уязвимости vault | CVSS3: 8.1 | 11 месяцев назад |
Уязвимостей на страницу