PT-2024-37162 · Hashicorp+1 · Hashicorp Vault+1

Alex Scheel

+1

·

Published

2024-06-12

·

Updated

2025-08-28

·

CVE-2024-5798

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions: HashiCorp Vault versions prior to 1.15.9 HashiCorp Vault versions prior to 1.16.3 HashiCorp Vault versions prior to 1.17.0
Description: The issue arises from improper validation of the JSON Web Token (JWT) role-bound audience claim when using the Vault JWT auth method. This may result in Vault validating a JWT even when the audience and role-bound claims do not match, allowing an invalid login to succeed.
Recommendations: For versions prior to 1.15.9, update to version 1.15.9 or later. For versions prior to 1.16.3, update to version 1.16.3 or later. For versions prior to 1.17.0, update to version 1.17.0 or later.

Fix

Improper Authorization

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-10836
BIT-VAULT-2024-5798
CVE-2024-5798
GHSA-32CJ-5WX4-GQ8P
GO-2024-2921

Affected Products

Hashicorp Vault
Red Os