PT-2024-2153 · Hashicorp+2 · Hashicorp Vault+2

D0Nut

·

Published

2024-03-04

·

Updated

2025-11-13

·

CVE-2024-2048

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HashiCorp Vault versions prior to 1.14.10 HashiCorp Vault versions prior to 1.15.5
Description The issue is related to errors in the procedure for confirming the authenticity of certificates. An attacker may be able to craft a malicious certificate to bypass authentication when the TLS certificate authentication method is configured with a non-CA certificate as a trusted certificate.
Recommendations For HashiCorp Vault versions prior to 1.14.10, update to version 1.14.10 or later to resolve the issue. For HashiCorp Vault versions prior to 1.15.5, update to version 1.15.5 or later to resolve the issue. As a temporary workaround, consider restricting the use of the TLS certificate authentication method until a patch is available.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-11859
ALT-PU-2024-12202
ALT-PU-2024-12204
ALT-PU-2024-12410
BDU:2024-02063
BIT-VAULT-2024-2048
CVE-2024-2048
GHSA-R3W7-MFPM-C2VW
GO-2024-2617

Affected Products

Alt Linux
Hashicorp Vault
Red Os