Логотип exploitDog
bind:CVE-2022-40186
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-40186

Количество 5

Количество 5

redhat логотип

CVE-2022-40186

почти 3 года назад

An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may allow for unintended access to key/value paths using that metadata in Vault.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2022-40186

почти 3 года назад

An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may allow for unintended access to key/value paths using that metadata in Vault.

CVSS3: 9.1
EPSS: Низкий
redos логотип

ROS-20250402-08

4 месяца назад

Уязвимость vault

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-7cgv-v83v-rr87

почти 3 года назад

HashiCorp Vault vulnerable to incorrect metadata access

CVSS3: 9.1
EPSS: Низкий
fstec логотип

BDU:2025-04009

почти 3 года назад

Уязвимость платформ для архивирования корпоративной информации HashiCorp Vault и Vault Enterprise, связанная с недостатками разграничения доступа, позволяющая нарушителю получить доступ к потенциально конфиденциальной информации

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-40186

An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may allow for unintended access to key/value paths using that metadata in Vault.

CVSS3: 9.1
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2022-40186

An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may allow for unintended access to key/value paths using that metadata in Vault.

CVSS3: 9.1
0%
Низкий
почти 3 года назад
redos логотип
ROS-20250402-08

Уязвимость vault

CVSS3: 9.1
0%
Низкий
4 месяца назад
github логотип
GHSA-7cgv-v83v-rr87

HashiCorp Vault vulnerable to incorrect metadata access

CVSS3: 9.1
0%
Низкий
почти 3 года назад
fstec логотип
BDU:2025-04009

Уязвимость платформ для архивирования корпоративной информации HashiCorp Vault и Vault Enterprise, связанная с недостатками разграничения доступа, позволяющая нарушителю получить доступ к потенциально конфиденциальной информации

CVSS3: 9.1
0%
Низкий
почти 3 года назад

Уязвимостей на страницу