CVE-2022-40186

An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may allow for unintended access to key/value paths using that metadata in Vault.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*

History

20 Jan 2023, 13:20

Type Values Removed Values Added
References (CONFIRM) https://security.netapp.com/advisory/ntap-20221111-0008/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20221111-0008/ - Third Party Advisory

14 Nov 2022, 15:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20221111-0008/ -

26 Sep 2022, 13:23

Type Values Removed Values Added
References (MISC) https://discuss.hashicorp.com - (MISC) https://discuss.hashicorp.com - Vendor Advisory
References (MISC) https://discuss.hashicorp.com/t/hcsec-2022-18-vault-entity-alias-metadata-may-leak-between-aliases-with-the-same-name-assigned-to-the-same-entity/44550 - (MISC) https://discuss.hashicorp.com/t/hcsec-2022-18-vault-entity-alias-metadata-may-leak-between-aliases-with-the-same-name-assigned-to-the-same-entity/44550 - Vendor Advisory
First Time Hashicorp vault
Hashicorp
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
CPE cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*

22 Sep 2022, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-09-22 01:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-40186

Mitre link : CVE-2022-40186

CVE.ORG link : CVE-2022-40186


JSON object : View

Products Affected

hashicorp

  • vault