CVE-2021-45042

MEDIUM

HashiCorp Vault 1.4.0-1.7.6, 1.8.0-1.8.5, 1.9.0 - Authenticated Denial of Service via KV Secrets Engine

Title source: llm
STIX 2.1

Description

In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.

References (3)

Core 3

Scores

CVSS v3 4.9
EPSS 0.0043
EPSS Percentile 63.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (2)
hashicorp/vault 1.9.0 (2 CPE variants)
hashicorp/vault 1.4.0 - 1.7.7 (2 CPE variants)
Published Dec 17, 2021
Tracked Since Feb 18, 2026