CVE-2022-25244

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/03/2022
Last modified:
18/03/2022

Description

Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenization key configuration endpoint to authorized operators with `read` permissions on this endpoint. Fixed in Vault Enterprise 1.9.4, 1.8.9 and 1.7.10.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* 1.7.0 (including) 1.7.10 (excluding)
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* 1.8.0 (including) 1.8.9 (excluding)
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* 1.9.0 (including) 1.9.4 (excluding)