CVE Vulnerabilities

CVE-2021-45042

Published: Dec 17, 2021 | Modified: Nov 21, 2024
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:C
RedHat/V2
RedHat/V3
4.9 MODERATE
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Ubuntu

In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.

Affected Software

Name Vendor Start Version End Version
Vault Hashicorp 1.4.0 (including) 1.7.7 (excluding)
Vault Hashicorp 1.8.0 (including) 1.8.6 (excluding)
Vault Hashicorp 1.9.0 (including) 1.9.0 (including)

References