
Cloud Vulnerability DB
A community-led vulnerabilities database
Vault and Vault Enterprise TLS certificates auth method contained a vulnerability (CVE-2024-2660) that failed to correctly validate OCSP responses when one or more OCSP sources were configured. The vulnerability affects Vault and Vault Enterprise versions from 1.14.0 and above, and has been fixed in Vault 1.16.0 and Vault Enterprise 1.16.1, 1.15.7, and 1.14.11. The issue was discovered and disclosed on April 4, 2024 (HashiCorp Discussion).
A bug was introduced in the OCSP response handling logic of Vault's TLS certificate authentication method that resulted in signatures and responses from multiple servers not being handled properly. The vulnerability has been assigned a CVSS v3.1 base score of 6.4 (Medium) with the vector string CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H, indicating that it requires adjacent network access and high privileges to exploit (HashiCorp Discussion).
The vulnerability could allow a malicious actor with privileged network access to successfully authenticate via Vault's TLS certificate authentication method with incorrect certificate status information. This could potentially lead to unauthorized access, disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS) (NetApp Advisory).
The vulnerability requires adjacent network access and high privileges to exploit. While public discussion of this vulnerability exists, no specific exploit details have been publicly disclosed (NetApp Advisory).
Customers using the TLS auth method with an OCSP server configured in their Vault installation should evaluate the risk associated with this issue and upgrade to the fixed versions: Vault 1.16.0 or newer, or Vault Enterprise 1.16.1, 1.15.7, 1.14.11, or newer. Users should refer to the Vault upgrading documentation for general guidance and version-specific upgrade notes (HashiCorp Discussion).
The vulnerability was identified by the Vault engineering team internally, demonstrating HashiCorp's proactive approach to security. The issue has been assigned a formal CVE identifier and has been acknowledged by major technology providers such as NetApp, who have begun investigating the potential impact on their products (HashiCorp Discussion).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."