Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-40186


An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may allow for unintended access to key/value paths using that metadata in Vault.


Published

2022-09-22T01:15:12.027

Last Modified

2025-05-27T18:15:29.850

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.1 (CRITICAL)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-639

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application hashicorp vault < 1.9.9 Yes
Application hashicorp vault < 1.9.9 Yes
Application hashicorp vault < 1.10.6 Yes
Application hashicorp vault < 1.10.6 Yes
Application hashicorp vault < 1.11.3 Yes
Application hashicorp vault < 1.11.3 Yes

References