All errata/c10f2/ALT-PU-2024-11915-4
ALT-PU-2024-11915-4

Package update vault in branch c10f2

Version1.13.12-alt5
Published2026-02-04
Max severityCRITICAL
Severity:

Closed issues (3)

BDU:2024-02063
HIGH8.1

Уязвимость платформ для архивирования корпоративной информации HashiCorp Vault и Vault Enterprise, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю обойти процесс аутентификации

Published: 2024-03-18Modified: 2024-08-06
CVSS 3.xHIGH 8.1
CVSS:3.x/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.0HIGH 7.6
CVSS:2.0/AV:N/AC:H/Au:N/C:C/I:C/A:C
References
CVE-2024-2048
CRITICAL9.8

Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In this configuration, an attacker may be able to craft a malicious certificate that could be used to bypass authentication. Fixed in Vault 1.15.5 and 1.14.10.

Published: 2024-03-04Modified: 2025-11-13
CVSS 3.xCRITICAL 9.8
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Closed bugs (1)

Для закрытия CVE-2024-2048 необходимо обновить пакет