CVE-2022-40186: Critical severity HashiCorp Vault vulnerability
An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may allow for unintended access to key/value paths using that metadata in Vault.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/hashicorp/vaultto a version that resolves this vulnerability.Fixed in 1.9.9 - Upgrade
Upgrade
go/github.com/hashicorp/vaultto a version that resolves this vulnerability.Fixed in 1.10.6 - Upgrade
Upgrade
go/github.com/hashicorp/vaultto a version that resolves this vulnerability.Fixed in 1.11.3
Event History
Frequently Asked Questions
What is CVE-2022-40186?
CVE-2022-40186 is a vulnerability in HashiCorp Vault and Vault Enterprise before 1.11.3 that allows metadata to be overwritten to the wrong alias.
How severe is CVE-2022-40186?
CVE-2022-40186 has a severity score of 9.1 out of 10.
What software versions are affected by CVE-2022-40186?
Versions of HashiCorp Vault and Vault Enterprise between 1.8.0 and 1.9.9, between 1.10.0 and 1.10.6, and between 1.11.0 and 1.11.3 are affected by CVE-2022-40186.
How can I fix CVE-2022-40186?
To fix CVE-2022-40186, update HashiCorp Vault and Vault Enterprise to version 1.11.3 or later.
Where can I find more information about CVE-2022-40186?
You can find more information about CVE-2022-40186 at the following references: [1](https://discuss.hashicorp.com), [2](https://discuss.hashicorp.com/t/hcsec-2022-18-vault-entity-alias-metadata-may-leak-between-aliases-with-the-same-name-assigned-to-the-same-entity/44550), [3](https://security.netapp.com/advisory/ntap-20221111-0008/).