Bug 2189514 (CVE-2022-25243) - CVE-2022-25243 vault: PKI Secrets Engine Policy Results In Incorrect Wildcard Certificate Issuance
Summary: CVE-2022-25243 vault: PKI Secrets Engine Policy Results In Incorrect Wildcard...
Keywords:
Status: NEW
Alias: CVE-2022-25243
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2223666 2223665
Blocks: 2223663
TreeView+ depends on / blocked
 
Reported: 2023-04-25 13:33 UTC by Pedro Sampaio
Modified: 2023-08-03 08:31 UTC (History)
8 users (show)

Fixed In Version: vault 1.8.9, vault 1.9.4
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in HashiCorp Vault and Vault Enterprise. This flaw allows a remote, authenticated attacker to bypass security restrictions caused by a flaw related to the PKI secrets engine under certain configurations. An attacker can issue wildcard certificates to authorized users for a specified domain by sending a specially crafted request.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Pedro Sampaio 2023-04-25 13:33:24 UTC
"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates to authorized users for a specified domain, even if the PKI role policy attribute allow_subdomains is set to false. Fixed in Vault Enterprise 1.8.9 and 1.9.4.

References:

https://discuss.hashicorp.com/t/hcsec-2022-09-vault-pki-secrets-engine-policy-results-in-incorrect-wildcard-certificate-issuance/36600
https://discuss.hashicorp.com
https://security.gentoo.org/glsa/202207-01


Note You need to log in before you can comment on or make changes to this bug.