First published: Thu Apr 22 2021(Updated: )
HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not validate TLS certificates when connecting to Cassandra clusters. Fixed in 1.6.4 and 1.7.1
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Vault | <1.6.4 | |
HashiCorp Vault | <1.6.4 | |
HashiCorp Vault | >=1.7.0<1.7.1 | |
HashiCorp Vault | >=1.7.0<1.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-27400.
The severity of CVE-2021-27400 is high with a severity value of 7.5.
HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) versions up to 1.6.4 and versions up to 1.7.1 are affected by CVE-2021-27400.
To fix this vulnerability, upgrade to HashiCorp Vault version 1.6.4 or 1.7.1.
You can find more information about CVE-2021-27400 at the following link: [link](https://discuss.hashicorp.com/t/hcsec-2021-10-vault-s-cassandra-integrations-did-not-validate-tls-certificates/23463)