Improper Certificate Validation in Vault Enterprise and Vault - CVE-2022-25243
Published: August 4, 2022
Vulnerability details
The vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists due to software allows the PKI secrets engine under certain configurations to issue wildcard
certificates to authorized users for a specified domain, even if the PKI
role policy attribute allow_subdomains is set to false. A remote user can bypass implemented security restriction and issue wildcard certificates.
Affected software
Vault
Gentoo Linux
How to mitigate CVE-2022-25243
Vault - addressed in versions 1.8.9, 1.9.4