Skip to content
vaultGHSA-7cgv-v83v-rr87

HashiCorp Vault vulnerable to incorrect metadata access

Critical9.1CVE-2022-40186 · Published Sep 23, 2022 · updated May 28, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/vault
Go
>= 1.11.0, < 1.11.31.11.3
>= 1.10.0, < 1.10.61.10.6
>= 1.8.0, < 1.9.91.9.9
Details and references

An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may allow for unintended access to key/value paths using that metadata in Vault.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-639
Also known as
BIT-vault-2022-40186, CVE-2022-40186, GO-2022-1021

More vault advisories

All
DateAdvisory
May 242022Token leases could outlive their TTL in HashiCorp Vault
CVE-2020-25816Critical9.8fixed in 1.5.4
May 182022HashiCorp Vault improper configuration of multi factor authentication
CVE-2022-30689Medium5.3fixed in 1.10.3
Mar 302023HashiCorp Vault's PKI mount vulnerable to denial of service
CVE-2023-0665Medium6.5fixed in 1.11.9, 1.12.5, 1.13.1
Mar 302023HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File
CVE-2023-0620Medium6.7fixed in 1.11.9, 1.12.5, 1.13.1
Mar 302023HashiCorp Vault's implementation of Shamir's secret sharing vulnerable to cache-timing attacks
CVE-2023-25000Medium4.7fixed in 1.11.9, 1.12.5, 1.13.1
Jun 92023Hashicorp Vault vulnerable to Cross-site Scripting
CVE-2023-2121Medium4.3fixed in 1.11.11, 1.12.7, 1.13.3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.