CVE-2021-27400

HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not validate TLS certificates when connecting to Cassandra clusters. Fixed in 1.6.4 and 1.7.1
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*

History

21 Nov 2024, 05:57

Type Values Removed Values Added
References () https://discuss.hashicorp.com/t/hcsec-2021-10-vault-s-cassandra-integrations-did-not-validate-tls-certificates/23463 - Vendor Advisory () https://discuss.hashicorp.com/t/hcsec-2021-10-vault-s-cassandra-integrations-did-not-validate-tls-certificates/23463 - Vendor Advisory

Information

Published : 2021-04-22 17:15

Updated : 2024-11-21 05:57


NVD link : CVE-2021-27400

Mitre link : CVE-2021-27400

CVE.ORG link : CVE-2021-27400


JSON object : View

Products Affected

hashicorp

  • vault
CWE
CWE-295

Improper Certificate Validation