CVE-2022-25244
Last modified
CVE-2022-25244 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenization key configuration endpoint to authorized operators with `read` permissions on this endpoint. Fixed in Vault Enterprise 1.9.4, 1.8.9 and 1.7.10.. EPSS estimates a 0.92% chance of exploitation in the next 30 days.
Description
Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenization key configuration endpoint to authorized operators with `read` permissions on this endpoint. Fixed in Vault Enterprise 1.9.4, 1.8.9 and 1.7.10.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hashicorp | Vault | >= 1.7.0, < 1.7.10 |
| Hashicorp | Vault | >= 1.8.0, < 1.8.9 |
| Hashicorp | Vault | >= 1.9.0, < 1.9.4 |
References
- https://discuss.hashicorp.comVendor Advisory
- https://discuss.hashicorp.comVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-25244?
How severe is CVE-2022-25244?
How do I fix CVE-2022-25244?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-25236xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attac…9.8
- CVE-2022-25237Bonita Web 2021.2 is affected by a authentication/authorizat…9.8
- CVE-2022-25238Silverstripe silverstripe/framework through 4.10.0 allows XS…5.4
- CVE-2022-25241In FileCloud before 21.3, the CSV user import functionality …8.8
- CVE-2022-25242In FileCloud before 21.3, file upload is not protected again…8.8
- CVE-2022-25243"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 a…6.5
- CVE-2022-25245Zoho ManageEngine ServiceDesk Plus before 13001 allows anyon…5.3
- CVE-2022-25246Axeda agent (All versions) and Axeda Desktop Server for Wind…8.8
- CVE-2022-25247Axeda agent (All versions) and Axeda Desktop Server for Wind…9.8
- CVE-2022-25248When connecting to a certain port Axeda agent (All versions)…5.3
- CVE-2022-25249When connecting to a certain port Axeda agent (All versions)…7.5
- CVE-2022-2525Improper Restriction of Excessive Authentication Attempts in…9.8
Are you affected by CVE-2022-25244?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
