CVE-2022-25243
MEDIUMVault 1.8.0-1.8.8 and 1.9.3 - Improper Certificate Validation in PKI Secrets Engine
Title source: llmDescription
"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates to authorized users for a specified domain, even if the PKI role policy attribute allow_subdomains is set to false. Fixed in Vault Enterprise 1.8.9 and 1.9.4.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_misc
https://discuss.hashicorp.com
Mitigation, Vendor Advisory x_refsource_misc
https://discuss.hashicorp.com/t/hcsec-2022-09-vault-pki-secrets-engine-policy-results-in-incorrect-wildcard-certificate-issuance/36600
Third Party Advisory vendor-advisory
x_refsource_gentoo
https://security.gentoo.org/glsa/202207-01
Scores
CVSS v3
6.5
EPSS
0.0018
EPSS Percentile
39.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-295
Status
published
Products (1)
hashicorp/vault
1.8.0 - 1.8.9 (2 CPE variants)
Published
Mar 10, 2022
Tracked Since
Feb 18, 2026