SB2021042180 - Multiple vulnerabilities in Vault Enterprise



SB2021042180 - Multiple vulnerabilities in Vault Enterprise

Published: April 21, 2021 Updated: April 17, 2026

Security Bulletin ID SB2021042180
Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Improper Certificate Validation (CVE-ID: CVE-2021-29653)

The vulnerability allows a remote user to bypass certificate revocation checks.

The vulnerability exists due to improper certificate revocation handling in the PKI Secrets Engine CRL generation logic when processing a tidy operation with tidy_revoked_certs enabled. A remote user can use a revoked but unexpired certificate to bypass certificate revocation checks.

Exploitation requires use of the PKI revocation mechanism and enforcement of the generated certificate revocation list, and only occurs when the tidy_revoked_certs setting is enabled.


2) Improper Certificate Validation (CVE-ID: CVE-2021-27400)

The vulnerability allows a remote attacker to intercept encrypted connections.

The vulnerability exists due to improper certificate validation in the Cassandra storage backend and Cassandra database secrets engine plugin when connecting to Cassandra clusters over TLS. A remote attacker can present an untrusted certificate to intercept encrypted connections.


Remediation

Install update from vendor's website.