VDB
CVE-2022-40186
CVE-2022-40186
PUBLISHED
An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may allow for unintended access to key/value paths using that metadata in Vault.
EPSS 0.81% · 54.2th percentile
Risk Scores
EPSS Score
0.81%
54.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | vault | 1.8.0, 1.11.0, 1.10.0 |
| Bitnami | vault | 1.8.0, 1.10.0, 1.11.0 |
Timeline
- Sep 20, 2022 CVE Published
- Sep 22, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Dec 21, 2022 EPSS Score
- Feb 3, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 20, 2023 EPSS Score
- May 4, 2023 EPSS Score
- Jun 18, 2023 EPSS Score
- Aug 1, 2023 EPSS Score
- Sep 15, 2023 EPSS Score
- Oct 30, 2023 EPSS Score