#VU66117 Improper Certificate Validation in Vault and Vault Enterprise - CVE-2022-25243
Published: August 4, 2022
Vault
Vault Enterprise
HashiCorp
Description
The vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists due to software allows the PKI secrets engine under certain configurations to issue wildcard
certificates to authorized users for a specified domain, even if the PKI
role policy attribute allow_subdomains is set to false. A remote user can bypass implemented security restriction and issue wildcard certificates.