Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenization key configuration endpoint to authorized operators with `read` permissions on this endpoint. Fixed in Vault Enterprise 1.9.4, 1.8.9 and 1.7.10.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-29941 Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenization key configuration endpoint to authorized operators with `read` permissions on this endpoint. Fixed in Vault Enterprise 1.9.4, 1.8.9 and 1.7.10.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T04:36:06.580Z

Reserved: 2022-02-16T00:00:00

Link: CVE-2022-25244

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-03-10T17:47:06.993

Modified: 2024-11-21T06:51:52.123

Link: CVE-2022-25244

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-03-10T00:00:00Z

Links: CVE-2022-25244 - Bugzilla

cve-icon OpenCVE Enrichment

No data.