CVE-2024-2048

Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In this configuration, an attacker may be able to craft a malicious certificate that could be used to bypass authentication. Fixed in Vault 1.15.5 and 1.14.10.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*

History

06 Aug 2025, 14:17

Type Values Removed Values Added
References () https://discuss.hashicorp.com/t/hcsec-2024-05-vault-cert-auth-method-did-not-correctly-validate-non-ca-certificates/63382 - () https://discuss.hashicorp.com/t/hcsec-2024-05-vault-cert-auth-method-did-not-correctly-validate-non-ca-certificates/63382 - Vendor Advisory
References () https://security.netapp.com/advisory/ntap-20240524-0009/ - () https://security.netapp.com/advisory/ntap-20240524-0009/ - Third Party Advisory
CPE cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*
First Time Hashicorp
Hashicorp vault

21 Nov 2024, 09:08

Type Values Removed Values Added
References () https://discuss.hashicorp.com/t/hcsec-2024-05-vault-cert-auth-method-did-not-correctly-validate-non-ca-certificates/63382 - () https://discuss.hashicorp.com/t/hcsec-2024-05-vault-cert-auth-method-did-not-correctly-validate-non-ca-certificates/63382 -
References () https://security.netapp.com/advisory/ntap-20240524-0009/ - () https://security.netapp.com/advisory/ntap-20240524-0009/ -

10 Jun 2024, 17:16

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20240524-0009/ -
Summary
  • (es) El método de autenticación de certificados TLS de Vault y Vault Enterprise (“Vault”) no validaba correctamente los certificados de cliente cuando se configuraba con un certificado que no era CA como certificado confiable. En esta configuración, un atacante puede crear un certificado malicioso que podría usarse para eludir la autenticación. Corregido en Vault 1.15.5 y 1.14.10.

04 Mar 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-04 20:15

Updated : 2025-08-06 14:17


NVD link : CVE-2024-2048

Mitre link : CVE-2024-2048

CVE.ORG link : CVE-2024-2048


JSON object : View

Products Affected

hashicorp

  • vault
CWE
CWE-295

Improper Certificate Validation