CVE Vulnerabilities

CVE-2021-45042

Published: Dec 17, 2021 | Modified: Sep 08, 2022
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:C
RedHat/V2
RedHat/V3
4.9 MODERATE
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Ubuntu

In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.

Affected Software

Name Vendor Start Version End Version
Vault Hashicorp 1.4.0 (including) 1.7.7 (excluding)
Vault Hashicorp 1.8.0 (including) 1.8.6 (excluding)
Vault Hashicorp 1.9.0 (including) 1.9.0 (including)

References