#VU87103 Improper authentication in Vault and Vault Enterprise - CVE-2024-2048
Published: March 4, 2024
Vault
Vault Enterprise
HashiCorp
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to improper validation of client TLS certificates when configured with a non-CA certificate as trusted certificate. A remote attacker can create a specially crafted certificate file to bypass authentication process and gain unauthorized access to the application.