CVE-2022-25243

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
10/03/2022
Last modified:
09/11/2022

Description

"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates to authorized users for a specified domain, even if the PKI role policy attribute allow_subdomains is set to false. Fixed in Vault Enterprise 1.8.9 and 1.9.4.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:* 1.8.0 (including) 1.8.9 (excluding)
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* 1.8.0 (including) 1.8.9 (excluding)
cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:* 1.9.0 (including) 1.9.4 (excluding)
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* 1.9.0 (including) 1.9.4 (excluding)