VDB

CVE-2022-40186

CVE-2022-40186 PUBLISHED

An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may allow for unintended access to key/value paths using that metadata in Vault.

EPSS 0.81% · 54.2th percentile

Risk Scores

EPSS Score
0.81%
54.2th percentile

Affected Products

VendorProductVersions
Bitnamivault1.8.0, 1.11.0, 1.10.0
Bitnamivault1.8.0, 1.10.0, 1.11.0

Timeline

  • Sep 20, 2022 CVE Published
  • Sep 22, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Dec 21, 2022 EPSS Score
  • Feb 3, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 20, 2023 EPSS Score
  • May 4, 2023 EPSS Score
  • Jun 18, 2023 EPSS Score
  • Aug 1, 2023 EPSS Score
  • Sep 15, 2023 EPSS Score
  • Oct 30, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›