PT-2021-17439 · Hashicorp+1 · Vault Enterprise+2

Martin Sucha

·

Published

2021-04-22

·

Updated

2024-03-06

·

CVE-2021-27400

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions HashiCorp Vault and Vault Enterprise versions prior to 1.6.4 HashiCorp Vault and Vault Enterprise versions prior to 1.7.1
Description The issue concerns the failure to validate TLS certificates when connecting to Cassandra clusters, affecting the storage backend and database secrets engine plugin.
Recommendations For versions prior to 1.6.4, update to version 1.6.4 or later. For versions prior to 1.7.1, update to version 1.7.1 or later.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

BIT-VAULT-2021-27400
CVE-2021-27400

Affected Products

Apache Cassandra
Hashicorp Vault
Vault Enterprise