Lucene search

K
osvGoogleOSV:CVE-2022-25244
HistoryMar 10, 2022 - 5:47 p.m.

CVE-2022-25244

2022-03-1017:47:06
Google
osv.dev
6

6.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.6%

Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenization key configuration endpoint to authorized operators with read permissions on this endpoint. Fixed in Vault Enterprise 1.9.4, 1.8.9 and 1.7.10.

CPENameOperatorVersion
vaulteq1.9.1
vaulteq1.9.3
vaulteq1.9.2
vaulteq1.9.0

6.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.6%