PT-2024-38439 · Hashicorp+2 · Hashicorp Vault Enterprise+3

Jörn Heissler

·

Published

2024-09-26

·

Updated

2025-11-13

·

CVE-2024-7594

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HashiCorp Vault Community Edition versions prior to 1.17.6 HashiCorp Vault Enterprise versions prior to 1.17.6, 1.16.10, and 1.15.15
Description The issue arises from the SSH secrets engine not requiring the valid principals list to contain a value by default. If the valid principals and default user fields of the SSH secrets engine configuration are not set, an SSH certificate requested by an authorized user to Vault's SSH secrets engine could be used to authenticate as any user on the host.
Recommendations For HashiCorp Vault Community Edition versions prior to 1.17.6, update to version 1.17.6 or later. For HashiCorp Vault Enterprise versions prior to 1.17.6, update to version 1.17.6 or later. For HashiCorp Vault Enterprise versions prior to 1.16.10, update to version 1.16.10 or later. For HashiCorp Vault Enterprise versions prior to 1.15.15, update to version 1.15.15 or later. As a temporary workaround, consider setting the valid principals and default user fields in the SSH secrets engine configuration to restrict access.

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

BDU:2025-08603
BIT-VAULT-2024-7594
CVE-2024-7594
GHSA-JG74-MWGW-V6X3
GO-2024-3162
OPENSUSE-SU-2024:0350-1
OPENSUSE-SU-2024:14447-1
OPENSUSE-SU-2024_3911-1
SUSE-SU-2024:3911-1

Affected Products

Hashicorp Vault Community Edition
Hashicorp Vault Enterprise
Red Os
Suse