CVE-2021-45042
MEDIUMHashiCorp Vault 1.4.0-1.7.6, 1.8.0-1.8.5, 1.9.0 - Authenticated Denial of Service via KV Secrets Engine
Title source: llmDescription
In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.
References (3)
Core 3
Core References
Product, Vendor Advisory x_refsource_misc
https://www.hashicorp.com/blog/category/vault
Vendor Advisory x_refsource_misc
https://discuss.hashicorp.com/t/hcsec2-21-33-vault-s-kv-secrets-engine-with-integrated-storage-exposed-to-authenticated-denial-of-service/33157
Third Party Advisory vendor-advisory
x_refsource_gentoo
https://security.gentoo.org/glsa/202207-01
Scores
CVSS v3
4.9
EPSS
0.0043
EPSS Percentile
63.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Details
Status
published
Products (2)
hashicorp/vault
1.9.0 (2 CPE variants)
hashicorp/vault
1.4.0 - 1.7.7 (2 CPE variants)
Published
Dec 17, 2021
Tracked Since
Feb 18, 2026