PT-2024-2960 · Hashicorp+1 · Vault Enterprise+2
Published
2024-04-04
·
Updated
2025-08-08
·
CVE-2024-2660
CVSS v3.1
6.8
Medium
| Vector | AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Vault versions 1.14.0 through 1.15.6
Vault Enterprise versions 1.14.0 through 1.14.10 and 1.15.0 through 1.15.6
Description
The issue is related to the incorrect validation of OCSP responses when one or more OCSP sources are configured in the TLS certificates auth method. This could potentially allow an attacker to bypass the authentication process.
Recommendations
For Vault versions 1.14.0 through 1.15.6, update to Vault 1.16.0 or later.
For Vault Enterprise versions 1.14.0 through 1.14.10, update to Vault Enterprise 1.14.11 or later.
For Vault Enterprise versions 1.15.0 through 1.15.6, update to Vault Enterprise 1.15.7 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Os
Vault
Vault Enterprise