Skip to content
VaultGHSA-32cj-5wx4-gq8p

HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims

Low2.6CVE-2024-5798 · Published Jun 12, 2024 · updated Aug 7, 2026

Vault and Vault Enterprise did not properly validate the JSON Web Token (JWT) role-bound audience claim when using the Vault JWT auth method. This may have resulted in Vault validating a JWT the audience and role-bound claims do not match, allowing an invalid login to succeed when it should have been rejected. This vulnerability, CVE-2024-5798, was fixed in Vault and Vault Enterprise 1.17.0, 1.16.3, and 1.15.9

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/vault
Go
>= 1.17.0-rc1, < 1.17.01.17.0
>= 1.16.0-rc1, < 1.16.31.16.3
>= 0.11.0, < 1.15.91.15.9
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-285
Also known as
BIT-vault-2024-5798, CVE-2024-5798, GO-2024-2921

More Vault advisories

All Vault
Advisory
Vault Community Edition privilege escalation vulnerability
High7.2Oct 10, 2024
Vault Leaks Client Token and Token Accessor in Audit Devices
Medium6.5Sep 2, 2024
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions
High7.5Jul 11, 2024
HashiCorpVault does not correctly validate OCSP responses
Medium6.4Apr 4, 2024
Incorrect TLS certificate auth method in Vault
High8.1Mar 4, 2024
Hashicorp Vault may expose sensitive log information
Medium4.5Feb 1, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.