#VU66116 Permissions, Privileges, and Access Controls in Vault Enterprise and Vault - CVE-2021-45042
Published: August 4, 2022
Vault Enterprise
Vault
HashiCorp
Description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly impose security restrictions in clusters using the Integrated Storage backend. A remote user with write permissions to a kv secrets engine can cause a panic and denial of service of the storage backend.