PT-2024-5874 · Hashicorp+2 · Vault Enterprise+3

Published

2024-07-11

·

Updated

2025-08-13

·

CVE-2024-6468

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Vault and Vault Enterprise versions prior to 1.15.12 Vault and Vault Enterprise versions prior to 1.16.6 Vault and Vault Enterprise versions prior to 1.17.2
Description The issue is related to the improper handling of requests originating from unauthorized IP addresses when the TCP listener option, proxy protocol behavior, is set to deny unauthorized. This can cause the Vault API server to shut down and no longer respond to any HTTP requests, potentially resulting in denial of service. The estimated number of potentially affected devices worldwide is not available.
Recommendations For Vault and Vault Enterprise versions prior to 1.15.12, update to version 1.15.12 or later. For Vault and Vault Enterprise versions prior to 1.16.6, update to version 1.16.6 or later. For Vault and Vault Enterprise versions prior to 1.17.2, update to version 1.17.2 or later. As a temporary workaround, consider disabling the deny unauthorized option for the proxy protocol behavior until a patch is available. Restrict access to the Vault API server to minimize the risk of exploitation. Avoid using the proxy protocol authorized addrs variable in the affected TCP listener option until the issue is resolved.

Fix

DoS

Weakness Enumeration

Related Identifiers

ALT-PU-2024-17120
ALT-PU-2024-17177
ALT-PU-2024-17272
ALT-PU-2024-17791
BDU:2024-06667
BIT-VAULT-2024-6468
CVE-2024-6468
GHSA-2QMW-PVF7-4MW6
GO-2024-2982

Affected Products

Alt Linux
Red Os
Vault
Vault Enterprise