CVE-2021-27400

HIGH

HashiCorp Vault <1.6.4, <1.7.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not validate TLS certificates when connecting to Cassandra clusters. Fixed in 1.6.4 and 1.7.1

Scores

CVSS v3 7.5
EPSS 0.0019
EPSS Percentile 40.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-295
Status published
Products (1)
hashicorp/vault < 1.6.4 (2 CPE variants)
Published Apr 22, 2021
Tracked Since Feb 18, 2026