Improper Certificate Validation in Vault Enterprise and Vault - CVE-2024-2660

 

Improper Certificate Validation in Vault Enterprise and Vault - CVE-2024-2660

Published: April 5, 2024


Vulnerability identifier: #VU88186
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-2660
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication.

The vulnerability exists due to the TLS certificates auth method does not correctly validate OCSP responses when one or more OCSP sources were configured. A remote attacker can successfully authenticate via Vault’s TLS certificate authentication method with incorrect certificate status information.


Affected software

Vault Enterprise
Vault
IBM Cloud Pak for Watson AIOps

How to mitigate CVE-2024-2660

Install updates from vendor's website.

Vault Enterprise - addressed in versions 1.14.11, 1.15.7, 1.16.1
Vault - addressed in versions 1.14.11, 1.15.7, 1.16.1
IBM Cloud Pak for Watson AIOps - update to 4.6.0

External References

Related Security Bulletins