CVE-2022-30689Hashicorp Vault vulnerability

5 documents4 sources
Severity
5.3MEDIUMNVD
EPSS
0.4%
top 41.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 17
Latest updateAug 21

Description

HashiCorp Vault and Vault Enterprise from 1.10.0 to 1.10.2 did not correctly configure and enforce MFA on login after server restarts. This affects the Login MFA feature introduced in Vault and Vault Enterprise 1.10.0 and does not affect the separate Enterprise MFA feature set. Fixed in 1.10.3.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDhashicorp/vault1.10.01.10.3
Gogithub.com/hashicorp_vault1.10.01.10.3

🔴Vulnerability Details

3
OSV
HashiCorp Vault improper configuration of multi factor authentication in github.com/hashicorp/vault2024-08-21
OSV
HashiCorp Vault improper configuration of multi factor authentication2022-05-18
GHSA
HashiCorp Vault improper configuration of multi factor authentication2022-05-18

📋Vendor Advisories

1
Red Hat
vault: incorrect MFA enforcement after server restart2022-05-17