QID 376492

Date Published: 2022-03-28

QID 376492: HashiCorp Vault Multiple Vulnerabilities

Vault is a tool for securely accessing secrets. A secret is anything that you want to tightly control access to, such as API keys, passwords, or certificates. Vault provides a unified interface to any secret while providing tight access control and recording a detailed audit log.

Affected version(s):
HashiCorp Vault version prior to 1.7.10
HashiCorp Vault version prior to 1.8.9
HashiCorp Vault version prior to 1.9.4

QID Detection Logic(Authenticated):
This QID detects vulnerable versions of Vault.

Successful exploitation of these vulnerabilities could affect Confidentiality and Integrity.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    The Vendor has released security update to fix the vulnerability. For more information please visit HCSEC-2022-08, HCSEC-2022-09

    Workaround:
    the "allow_bare_domains" attribute is false by default and must be explicitly enabled by an operator to fix vulnerability associated with HCSEC-2022-09.

    CVEs related to QID 376492

    Software Advisories
    Advisory ID Software Component Link
    HCSEC-2022-08 URL Logo discuss.hashicorp.com/t/hcsec-2022-08-vault-enterprise-s-tokenization-transform-configuration-endpoint-may-expose-transform-key/36599
    HCSEC-2022-09 URL Logo discuss.hashicorp.com/t/hcsec-2022-09-vault-pki-secrets-engine-policy-results-in-incorrect-wildcard-certificate-issuance/36600