First published: Mon Mar 07 2022(Updated: )
"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates to authorized users for a specified domain, even if the PKI role policy attribute allow_subdomains is set to false. Fixed in Vault Enterprise 1.8.9 and 1.9.4.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Vault | >=1.8.0<1.8.9 | |
HashiCorp Vault | >=1.8.0<1.8.9 | |
HashiCorp Vault | >=1.9.0<1.9.4 | |
HashiCorp Vault | >=1.9.0<1.9.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-25243.
The severity of CVE-2022-25243 is medium with a CVSS score of 6.5.
Vault and Vault Enterprise versions 1.8.0 through 1.8.8 and 1.9.0 through 1.9.3 are affected by CVE-2022-25243.
CVE-2022-25243 allows the PKI secrets engine to issue wildcard certificates to authorized users for a specified domain, even if the allow_subdomains attribute is set to false.
You can fix CVE-2022-25243 by upgrading to Vault Enterprise version 1.8.9 or 1.9.4.