2024-06-10 18:03:10 +00:00

63 lines
2.0 KiB
JSON

{
"id": "CVE-2024-2660",
"sourceIdentifier": "security@hashicorp.com",
"published": "2024-04-04T18:15:14.783",
"lastModified": "2024-06-10T17:16:25.443",
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
"lang": "en",
"value": "Vault and Vault Enterprise TLS certificates auth method did not correctly validate OCSP responses when one or more OCSP sources were configured. Fixed in Vault 1.16.0 and Vault Enterprise 1.16.1, 1.15.7, and 1.14.11."
},
{
"lang": "es",
"value": "El m\u00e9todo de autenticaci\u00f3n de los certificados TLS de Vault y Vault Enterprise no validaba correctamente las respuestas de OCSP cuando se configuraban uno o m\u00e1s or\u00edgenes de OCSP. Se corrigi\u00f3 en Vault 1.16.0 y Vault Enterprise 1.16.1, 1.15.7 y 1.14.11."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "security@hashicorp.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "ADJACENT_NETWORK",
"attackComplexity": "HIGH",
"privilegesRequired": "HIGH",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 6.4,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 0.5,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "security@hashicorp.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-703"
}
]
}
],
"references": [
{
"url": "https://discuss.hashicorp.com/t/hcsec-2024-07-vault-tls-cert-auth-method-did-not-correctly-validate-ocsp-responses/64573",
"source": "security@hashicorp.com"
},
{
"url": "https://security.netapp.com/advisory/ntap-20240524-0007/",
"source": "security@hashicorp.com"
}
]
}