VDB
CVE-2024-2048
CVE-2024-2048
PUBLISHED
CVSS 9.800000190734863 CRITICAL
Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In this configuration, an attacker may be able to craft a malicious certificate that could be used to bypass authentication. Fixed in Vault 1.15.5 and 1.14.10.
EPSS 0.45% · 37.2th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.45%
37.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | vault | 1.15.5 |
| Bitnami | vault | 1.15.5 |
Timeline
- Mar 4, 2024 CVE Published
- Mar 4, 2024 PoC Published
- Mar 4, 2024 PoC Published
- Mar 5, 2024 EPSS Score
- Mar 31, 2024 EPSS Score
- Apr 27, 2024 EPSS Score
- May 23, 2024 EPSS Score
- Jun 19, 2024 EPSS Score
- Jul 15, 2024 EPSS Score
- Aug 14, 2024 EPSS Score
- Sep 10, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score