Certificate Validation Bypass Vulnerability

CVE-2024-2048
8.1HIGH

Key Information

Vendor
Hashicorp
Status
Vault
Vault Enterprise
Vendor
CVE Published:
4 March 2024

Badges

😄 Trended📰 News Worthy

Summary

CVE-2024-2048 is a vulnerability in HashiCorp's Vault and Vault Enterprise software, with a CVSS score of 8.1. This vulnerability allows attackers to bypass authentication and gain unauthorized access to sensitive data stored within the software. The issue is related to the incorrect validation of client certificates, specifically when configured with a non-CA certificate as a trusted certificate. A malicious actor could exploit this vulnerability to craft a fake certificate and gain access to valuable secrets, including API keys, passwords, and other critical information. While the vulnerability has not been exploited in the wild, the potential impact of its exploitation is significant. Compromised credentials could lead to the disruption of business systems and operations, as well as the theft and misuse of sensitive data. The vendor, HashiCorp, has released patches to address the vulnerability in versions 1.15.5 and 1.14.10, and organizations are urged to upgrade their software immediately. Additionally, organizations should investigate historical evidence of unauthorized activity within their Vault software, as patching alone cannot undo past compromises. Overall, the exploitation of CVE-2024-2048 poses a significant threat, and prompt action is necessary to mitigate the risk of unauthorized access and data theft.

Affected Version(s)

Vault < 1.16.0

Vault Enterprise < 1.16.0

News Articles

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability started trending.

  • First article discovered by securityonline.info

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database1 News Article(s)
.