vaultGHSA-j2rp-gmqv-frhv
HashiCorpVault does not correctly validate OCSP responses
Medium6.4CVE-2024-2660 · Published Apr 4, 2024 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/vault Go | < 1.16.0 | 1.16.0 |
Details and references
Vault and Vault Enterprise TLS certificates auth method did not correctly validate OCSP responses when one or more OCSP sources were configured. Fixed in Vault 1.16.0 and Vault Enterprise 1.16.1, 1.15.7, and 1.14.11.
More vault advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 42024 | Incorrect TLS certificate auth method in Vault CVE-2024-2048High8.1fixed in 1.14.10, 1.15.5 | High8.1 | 1.14.10, 1.15.5 |
| Feb 12024 | Hashicorp Vault may expose sensitive log information CVE-2024-0831Medium4.5fixed in 1.15.5 | Medium4.5 | 1.15.5 |
| Jan 312024 | Improper Authentication in HashiCorp Vault CVE-2021-3282High7.5fixed in 1.6.2 | High7.5 | 1.6.2 |
| Jan 312024 | Enumeration of users in HashiCorp Vault CVE-2020-35177Medium6.5fixed in 1.5.6, 1.6.1 | Medium6.5 | 1.5.6, 1.6.1 |
| Jan 312024 | HashiCorp Vault Authentication bypass CVE-2020-16251High8.2fixed in 1.2.5, 1.3.8, 1.4.4, 1.5.1 | High8.2 | 1.2.5, 1.3.8, 1.4.4, 1.5.1 |
| Jan 302024 | HashiCorp Vault Improper Privilege Management CVE-2020-10660Medium5.3fixed in 1.3.4 | Medium5.3 | 1.3.4 |