Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-2048


Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In this configuration, an attacker may be able to craft a malicious certificate that could be used to bypass authentication. Fixed in Vault 1.15.5 and 1.14.10.


Published

2024-03-04T20:15:50.690

Last Modified

2025-11-13T17:51:43.380

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-295

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application hashicorp vault < 1.14.10 Yes
Application hashicorp vault < 1.14.10 Yes
Application hashicorp vault < 1.15.5 Yes
Application hashicorp vault < 1.15.5 Yes
Application openbao openbao < 2.0.0 Yes

References