Incorrect TLS certificate auth method in Vault
High severity
GitHub Reviewed
Published
Mar 4, 2024
to the GitHub Advisory Database
•
Updated Jun 10, 2024
Package
Affected versions
>= 1.15.0, < 1.15.5
< 1.14.10
Patched versions
1.15.5
1.14.10
Description
Published by the National Vulnerability Database
Mar 4, 2024
Published to the GitHub Advisory Database
Mar 4, 2024
Reviewed
Mar 6, 2024
Last updated
Jun 10, 2024
Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In this configuration, an attacker may be able to craft a malicious certificate that could be used to bypass authentication. Fixed in Vault 1.15.5 and 1.14.10.
References