First published: Mon Mar 07 2022(Updated: )
Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenization key configuration endpoint to authorized operators with `read` permissions on this endpoint. Fixed in Vault Enterprise 1.9.4, 1.8.9 and 1.7.10.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Vault | >=1.7.0<1.7.10 | |
HashiCorp Vault | >=1.8.0<1.8.9 | |
HashiCorp Vault | >=1.9.0<1.9.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25244 is a vulnerability in Vault Enterprise clusters using the tokenization transform feature that can expose the tokenization key through the tokenization key configuration endpoint.
CVE-2022-25244 affects HashiCorp Vault Enterprise versions 1.7.0 to 1.7.10, 1.8.0 to 1.8.9, and 1.9.0 to 1.9.4.
CVE-2022-25244 has a severity rating of medium with a CVSS score of 6.5.
To fix CVE-2022-25244, upgrade to Vault Enterprise version 1.9.4, 1.8.9, or 1.7.10.