First published: Thu Sep 22 2022(Updated: )
An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may allow for unintended access to key/value paths using that metadata in Vault.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Vault | >=1.8.0<1.9.9 | |
HashiCorp Vault | >=1.8.0<1.9.9 | |
HashiCorp Vault | >=1.10.0<1.10.6 | |
HashiCorp Vault | >=1.10.0<1.10.6 | |
HashiCorp Vault | >=1.11.0<1.11.3 | |
HashiCorp Vault | >=1.11.0<1.11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40186 is a vulnerability in HashiCorp Vault and Vault Enterprise before 1.11.3 that allows metadata to be overwritten to the wrong alias.
CVE-2022-40186 has a severity score of 9.1 out of 10.
Versions of HashiCorp Vault and Vault Enterprise between 1.8.0 and 1.9.9, between 1.10.0 and 1.10.6, and between 1.11.0 and 1.11.3 are affected by CVE-2022-40186.
To fix CVE-2022-40186, update HashiCorp Vault and Vault Enterprise to version 1.11.3 or later.
You can find more information about CVE-2022-40186 at the following references: [1](https://discuss.hashicorp.com), [2](https://discuss.hashicorp.com/t/hcsec-2022-18-vault-entity-alias-metadata-may-leak-between-aliases-with-the-same-name-assigned-to-the-same-entity/44550), [3](https://security.netapp.com/advisory/ntap-20221111-0008/).