CVE-2024-2048: Vault Cert Auth Method Did Not Correctly Validate Non-CA Certificates
Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In this configuration, an attacker may be able to craft a malicious certificate that could be used to bypass authentication. Fixed in Vault 1.15.5 and 1.14.10.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2048?
CVE-2024-2048 has a medium severity rating due to the potential for an attacker to exploit the vulnerability using malformed certificates.
How do I fix CVE-2024-2048?
To fix CVE-2024-2048, upgrade Vault to version 1.14.10 or 1.15.5 or later.
What software is affected by CVE-2024-2048?
CVE-2024-2048 affects Vault versions less than 1.14.10 and between 1.15.0 and 1.15.5.
What is the impact of CVE-2024-2048?
The impact of CVE-2024-2048 may allow attackers to bypass authentication using maliciously crafted non-CA certificates.
Is CVE-2024-2048 fixed in the latest version of Vault?
Yes, CVE-2024-2048 is fixed in Vault versions 1.14.10 and 1.15.5.