Improper Certificate Validation in Vault and Vault Enterprise - CVE-2021-27400
Published: April 21, 2021 / Updated: April 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to intercept encrypted connections.
The vulnerability exists due to improper certificate validation in the Cassandra storage backend and Cassandra database secrets engine plugin when connecting to Cassandra clusters over TLS. A remote attacker can present an untrusted certificate to intercept encrypted connections.
Affected software
Vault Enterprise
How to mitigate CVE-2021-27400
Vault Enterprise - addressed in versions 1.6.4, 1.7.1