Improper authentication in Vault Enterprise and Vault - CVE-2024-2048
Published: March 4, 2024
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to improper validation of client TLS certificates when configured with a non-CA certificate as trusted certificate. A remote attacker can create a specially crafted certificate file to bypass authentication process and gain unauthorized access to the application.
Affected software
Vault
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2024-2048
Vault - addressed in versions 1.14.10, 1.15.5
IBM Cloud Pak for Watson AIOps - update to 4.5.0