Skip to content
vaultGHSA-c5wc-v287-82pc

HashiCorp Vault improper configuration of multi factor authentication

Medium5.3CVE-2022-30689 · Published May 18, 2022 · updated Aug 21, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/vault
Go
>= 1.10.0, < 1.10.31.10.3
Details and references

HashiCorp Vault and Vault Enterprise from 1.10.0 to 1.10.2 did not correctly configure and enforce MFA on login after server restarts. This affects the Login MFA feature introduced in Vault and Vault Enterprise 1.10.0 and does not affect the separate Enterprise MFA feature set. Fixed in 1.10.3.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Severity from
GitHub (reviewed advisory)
Also known as
BIT-vault-2022-30689, CVE-2022-30689, GO-2022-0590

More vault advisories

All
DateAdvisory
May 242022Token leases could outlive their TTL in HashiCorp Vault
CVE-2020-25816Critical9.8fixed in 1.5.4
Sep 232022HashiCorp Vault vulnerable to incorrect metadata access
CVE-2022-40186Critical9.1fixed in 1.9.9, 1.10.6, 1.11.3
Dec 22021HashiCorp Vault Incorrect Permission Assignment for Critical Resource
CVE-2021-43998Critical9.1fixed in 1.7.6, 1.8.5
Oct 122021Incorrect Privilege Assignment in HashiCorp Vault
CVE-2021-42135High8.1no fix yet
Oct 122021Hashicorp Vault Privilege Escalation Vulnerability
CVE-2021-41802Low2.9fixed in 1.7.5, 1.8.4
Aug 302021HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0
CVE-2021-38553Critical9.8fixed in 1.8.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.