Improper Authentication in Vault Enterprise and Vault - CVE-2022-41316

 

Improper Authentication in Vault Enterprise and Vault - CVE-2022-41316

Published: October 12, 2022


Vulnerability identifier: #VU68254
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-41316
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in the Certificate Revocation Lists (CRLs) implementation, which prevented Vault from denying access to users with revoked certificates without application reboot. As a result, when using TLS certificate authentication, Vault did not correctly perform CRL revocation checks if login occurred between Vault startup (or invalidation) and a manual retrieval of the CRL, allowing users to continue using the application with revoked certificates.


Affected software

Vault Enterprise
Vault
IBM Cloud Pak for Watson AIOps
Red Hat OpenShift Container Platform
OpenShift Data Foundation (formerly OpenShift Container Storage)

How to mitigate CVE-2022-41316

Install updates from vendor's website.

Vault Enterprise - addressed in versions 1.9.10, 1.10.7, 1.11.4
Vault - addressed in versions 1.9.10, 1.10.7, 1.11.4
IBM Cloud Pak for Watson AIOps - update to 3.5.1
Red Hat OpenShift Container Platform - addressed in versions 4.12.0, 4.13.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0

External References

Related Security Bulletins