CVE-2021-45042

MEDIUMCVSS 4.9/10EPSS 1.41%

Last modified

CVE-2021-45042 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.. EPSS estimates a 1.41% chance of exploitation in the next 30 days.

Description

In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.

Metrics

CVSS 3.1
4.9/10

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
1.41%

69.2th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
HashicorpVault>= 1.4.0, < 1.7.7
HashicorpVault>= 1.8.0, < 1.8.6
HashicorpVault1.9.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-45042?
In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.
How severe is CVE-2021-45042?
CVE-2021-45042 has a CVSS score of 4.9/10 (MEDIUM severity). The EPSS model estimates a 1.41% probability of exploitation in the next 30 days.
How do I fix CVE-2021-45042?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-45042?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST