CVE-2024-2048

Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In this configuration, an attacker may be able to craft a malicious certificate that could be used to bypass authentication. Fixed in Vault 1.15.5 and 1.14.10.
Configurations

No configuration.

History

10 Jun 2024, 17:16

Type Values Removed Values Added
Summary
  • (es) El método de autenticación de certificados TLS de Vault y Vault Enterprise (“Vault”) no validaba correctamente los certificados de cliente cuando se configuraba con un certificado que no era CA como certificado confiable. En esta configuración, un atacante puede crear un certificado malicioso que podría usarse para eludir la autenticación. Corregido en Vault 1.15.5 y 1.14.10.
References
  • () https://security.netapp.com/advisory/ntap-20240524-0009/ -

04 Mar 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-04 20:15

Updated : 2024-06-10 17:16


NVD link : CVE-2024-2048

Mitre link : CVE-2024-2048

CVE.ORG link : CVE-2024-2048


JSON object : View

Products Affected

No product.

CWE
CWE-295

Improper Certificate Validation