CVE-2022-25244

Description

Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenization key configuration endpoint to authorized operators with read permissions on this endpoint. Fixed in Vault Enterprise 1.9.4, 1.8.9 and 1.7.10.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.281

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2022-25243,CVE-2022-25244 are affected in HashiCorp Vault Enterprise 1.8.8Windows
Vulnerabilities CVE-2022-25243,CVE-2022-25244 are affected in HashiCorp Vault Enterprise 1.9.3Windows
Vulnerabilities CVE-2022-25244 are affected in HashiCorp Vault Enterprise 1.7.9Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234