Description
Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In this configuration, an attacker may be able to craft a malicious certificate that could be used to bypass authentication. Fixed in Vault 1.15.5 and 1.14.10.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0996 | Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In this configuration, an attacker may be able to craft a malicious certificate that could be used to bypass authentication. Fixed in Vault 1.15.5 and 1.14.10. |
Github GHSA |
GHSA-r3w7-mfpm-c2vw | Incorrect TLS certificate auth method in Vault |
References
History
Thu, 13 Nov 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openbao
Openbao openbao |
|
| CPEs | cpe:2.3:a:openbao:openbao:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openbao
Openbao openbao |
Wed, 06 Aug 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:* cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* |
Fri, 14 Feb 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hashicorp
Hashicorp vault Hashicorp vault Enterprise |
|
| CPEs | cpe:2.3:a:hashicorp:vault:1.15.5:*:*:*:*:*:*:* cpe:2.3:a:hashicorp:vault_enterprise:1.15.5:*:*:*:*:*:*:* |
|
| Vendors & Products |
Hashicorp
Hashicorp vault Hashicorp vault Enterprise |
|
| Metrics |
ssvc
|
Thu, 13 Feb 2025 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2025-02-13T17:32:32.417Z
Reserved: 2024-03-01T00:03:34.034Z
Link: CVE-2024-2048
Updated: 2024-08-01T19:03:37.841Z
Status : Analyzed
Published: 2024-03-04T20:15:50.690
Modified: 2025-11-13T17:51:43.380
Link: CVE-2024-2048
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA