CVE-2022-36129
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
26/07/2022
Last modified:
08/08/2023
Description
HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that could be abused to override the voter status of a node within a Vault HA cluster, introducing potential for future data loss or catastrophic failure. Fixed in Vault Enterprise 1.9.8, 1.10.5, and 1.11.1.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:hashicorp:vault:*:*:*:*:*:*:*:* | 1.7.0 (including) | 1.9.7 (including) |
| cpe:2.3:a:hashicorp:vault:*:*:*:*:*:*:*:* | 1.10.0 (including) | 1.10.4 (including) |
| cpe:2.3:a:hashicorp:vault:1.11.0:*:*:*:-:*:*:* | ||
| cpe:2.3:a:hashicorp:vault:1.11.0:*:*:*:enterprise:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



