CVE-2021-45042
Last modified
CVE-2021-45042 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.. EPSS estimates a 1.41% chance of exploitation in the next 30 days.
Description
In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hashicorp | Vault | >= 1.4.0, < 1.7.7 |
| Hashicorp | Vault | >= 1.8.0, < 1.8.6 |
| Hashicorp | Vault | 1.9.0 |
References
- https://security.gentoo.org/glsa/202207-01Third Party Advisory
- https://www.hashicorp.com/blog/category/vaultProduct, Vendor Advisory
- https://security.gentoo.org/glsa/202207-01Third Party Advisory
- https://www.hashicorp.com/blog/category/vaultProduct, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-45042?
How severe is CVE-2021-45042?
How do I fix CVE-2021-45042?
Are you affected by CVE-2021-45042?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
