vaultGHSA-c5wc-v287-82pc
HashiCorp Vault improper configuration of multi factor authentication
Medium5.3CVE-2022-30689 · Published May 18, 2022 · updated Aug 21, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/vault Go | >= 1.10.0, < 1.10.3 | 1.10.3 |
Details and references
HashiCorp Vault and Vault Enterprise from 1.10.0 to 1.10.2 did not correctly configure and enforce MFA on login after server restarts. This affects the Login MFA feature introduced in Vault and Vault Enterprise 1.10.0 and does not affect the separate Enterprise MFA feature set. Fixed in 1.10.3.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Also known as
- BIT-vault-2022-30689, CVE-2022-30689, GO-2022-0590
More vault advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 242022 | Token leases could outlive their TTL in HashiCorp Vault CVE-2020-25816Critical9.8fixed in 1.5.4 | Critical9.8 | 1.5.4 |
| Sep 232022 | HashiCorp Vault vulnerable to incorrect metadata access CVE-2022-40186Critical9.1fixed in 1.9.9, 1.10.6, 1.11.3 | Critical9.1 | 1.9.9, 1.10.6, 1.11.3 |
| Dec 22021 | HashiCorp Vault Incorrect Permission Assignment for Critical Resource CVE-2021-43998Critical9.1fixed in 1.7.6, 1.8.5 | Critical9.1 | 1.7.6, 1.8.5 |
| Oct 122021 | Incorrect Privilege Assignment in HashiCorp Vault CVE-2021-42135High8.1no fix yet | High8.1 | No fix yet |
| Oct 122021 | Hashicorp Vault Privilege Escalation Vulnerability CVE-2021-41802Low2.9fixed in 1.7.5, 1.8.4 | Low2.9 | 1.7.5, 1.8.4 |
| Aug 302021 | HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0 CVE-2021-38553Critical9.8fixed in 1.8.0 | Critical9.8 | 1.8.0 |