VYPR
Moderate severityNVD Advisory· Published Apr 4, 2024· Updated Sep 26, 2024

Vault TLS Cert Auth Method Did Not Correctly Validate OCSP Responses

CVE-2024-2660

Description

Vault and Vault Enterprise TLS certificates auth method did not correctly validate OCSP responses when one or more OCSP sources were configured. This vulnerability, CVE-2024-2660, affects Vault and Vault Enterprise 1.14.0 and above, and is fixed in Vault 1.16.0 and Vault Enterprise 1.16.1, 1.15.7, and 1.14.11.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/hashicorp/vaultGo
< 1.16.01.16.0

Affected products

2
  • Range: 1.14.0
  • HashiCorp/Vault Enterprisev5
    Range: 1.14.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.