CVE-2022-40186
Published on: Not Yet Published
Last Modified on: 01/20/2023 01:20:00 PM UTC
Certain versions of Vault from Hashicorp contain the following vulnerability:
An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may allow for unintended access to key/value paths using that metadata in Vault.
- CVE-2022-40186 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
CVSS3 Score: 9.1 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
CVE-2022-40186 HashiCorp Vault Vulnerability in NetApp Products | NetApp Product Security | security.netapp.com text/html |
![]() |
HashiCorp Discuss | discuss.hashicorp.com text/html |
![]() |
HCSEC-2022-18 - Vault Entity Alias Metadata May Leak Between Aliases With The Same Name Assigned To The Same Entity - Security - HashiCorp Discuss | discuss.hashicorp.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Hashicorp | Vault | All | All | All | All |
Application | Hashicorp | Vault | All | All | All | All |
- cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*:
- cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-40186 : An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in… twitter.com/i/web/status/1… | 2022-09-22 01:07:52 |
![]() |
New Vulnerability: CVE-2022-40186 #InceptusSecure #UnderOurProtection | 2022-09-22 05:18:27 |
![]() |
CVE-2022-40186 | 2022-09-22 02:38:23 |