4.9
CVSSv3

CVE-2021-45042

Published: 17/12/2021 Updated: 08/09/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
VMScore: 605
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:C

Vulnerability Summary

In HashiCorp Vault and Vault Enterprise prior to 1.7.7, 1.8.x prior to 1.8.6, and 1.9.x prior to 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hashicorp vault 1.9.0

hashicorp vault

Vendor Advisories

In HashiCorp Vault and Vault Enterprise before 177, 18x before 186, and 19x before 191, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend The earliest affected version is 140 ...