CVE-2024-2048

CVSS V2 None CVSS V3 None
Description
Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In this configuration, an attacker may be able to craft a malicious certificate that could be used to bypass authentication. Fixed in Vault 1.15.5 and 1.14.10.
Overview
  • CVE ID
  • CVE-2024-2048
  • Assigner
  • HashiCorp
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-03-04T19:56:47.253Z
  • Last Modified Date
  • 2024-03-04T19:56:47.253Z
History
Created Old Value New Value Data Type Notes
2024-06-25 23:11:03 Added to TrackCVE