Lucene search

K
cveHashiCorpCVE-2024-2660
HistoryApr 04, 2024 - 6:15 p.m.

CVE-2024-2660

2024-04-0418:15:14
CWE-636
HashiCorp
web.nvd.nist.gov
51
vault
enterprise
tls
certificates
authentication
method
ocsp
validation
nvd
cve-2024-2660
vulnerability

CVSS3

6.4

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

6.5

Confidence

High

EPSS

0

Percentile

9.0%

Vault and Vault Enterprise TLS certificates auth method did not correctly validate OCSP responses when one or more OCSP sources were configured. This vulnerability, CVE-2024-2660, affects Vault and Vault Enterprise 1.14.0 and above, and is fixed in Vault 1.16.0 and Vault Enterprise 1.16.1, 1.15.7, and 1.14.11.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "64 bit",
      "32 bit",
      "x86",
      "ARM",
      "MacOS",
      "Windows",
      "Linux"
    ],
    "product": "Vault",
    "repo": "https://github.com/hashicorp/vault",
    "vendor": "HashiCorp",
    "versions": [
      {
        "lessThan": "1.16.0",
        "status": "affected",
        "version": "1.14.0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "64 bit",
      "32 bit",
      "x86",
      "ARM",
      "MacOS",
      "Windows",
      "Linux"
    ],
    "product": "Vault Enterprise",
    "repo": "https://github.com/hashicorp/vault",
    "vendor": "HashiCorp",
    "versions": [
      {
        "changes": [
          {
            "at": "1.14.11",
            "status": "unaffected"
          },
          {
            "at": "1.15.7",
            "status": "unaffected"
          }
        ],
        "lessThan": "1.16.0",
        "status": "affected",
        "version": "1.14.0",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

6.4

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

6.5

Confidence

High

EPSS

0

Percentile

9.0%