VDB
WID-SEC-W-2024-2239
WID-SEC-W-2024-2239
PUBLISHED
Vault ist ein identitätsbasiertes System zur Verwaltung von Geheimnissen und Verschlüsselung.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hashicorp Vault <1.17.6 | ||
| Hashicorp Vault <1.15.15 | ||
| Hashicorp Vault 1.16.10 | ||
| Hashicorp Vault 1.15.15 | ||
| Hashicorp Vault 1.17.6 | ||
| Hashicorp Vault <1.16.10 |
Timeline
- Sep 26, 2024 CVE Published
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-2239.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-2239 advisory
- https://discuss.hashicorp.com/t/hcsec-2024-20-vault-ssh-secrets-engine-configuration-did-not-restrict-valid-principals-by-default/70251 url
- https://bugzilla.redhat.com/show_bug.cgi?id=2315013 url
- https://github.com/advisories/GHSA-jg74-mwgw-v6x3 url