vault: PKI Secrets Engine Policy Results In Incorrect Wildcard Certificate Issuance
Published Mar 7, 2022
6.5
MEDIUMCVSS 3.1
EPSS 0.57%
Description
"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates to authorized users for a specified domain, even if the PKI role policy attribute allow_subdomains is set to false. Fixed in Vault Enterprise 1.8.9 and 1.9.4.
Affected products
No data.
No data.
Red Hat OpenShift Container Platform 4
openshift4/ose-installer
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/topology-aware-lifecycle-manager-rhel8-operator
Not affected
Red Hat Openshift Container Storage 4
ocs4/cephcsi-rhel8
Out of support scope
Red Hat Openshift Container Storage 4
ocs4/mcg-rhel8-operator
Out of support scope
Red Hat Openshift Container Storage 4
ocs4/ocs-rhel8-operator
Out of support scope
Red Hat Openshift Container Storage 4
ocs4/rook-ceph-rhel8-operator
Out of support scope
Red Hat Openshift Data Foundation 4
odf4/cephcsi-rhel9
Not affected
Red Hat Openshift Data Foundation 4
odf4/mcg-rhel9-operator
Will not fix
Red Hat Openshift Data Foundation 4
odf4/ocs-rhel9-operator
Not affected
Red Hat Openshift Data Foundation 4
odf4/odf-rhel9-operator
Not affected
Red Hat Openshift Data Foundation 4
odf4/rook-ceph-rhel8-operator
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | openshift4/ose-installer | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/topology-aware-lifecycle-manager-rhel8-operator | Not affected | n/a |
| Red Hat Openshift Container Storage 4 | ocs4/cephcsi-rhel8 | Out of support scope | n/a |
| Red Hat Openshift Container Storage 4 | ocs4/mcg-rhel8-operator | Out of support scope | n/a |
| Red Hat Openshift Container Storage 4 | ocs4/ocs-rhel8-operator | Out of support scope | n/a |
| Red Hat Openshift Container Storage 4 | ocs4/rook-ceph-rhel8-operator | Out of support scope | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/cephcsi-rhel9 | Not affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/mcg-rhel9-operator | Will not fix | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/ocs-rhel9-operator | Not affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/odf-rhel9-operator | Not affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/rook-ceph-rhel8-operator | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- https://access.redhat.com/security/cve/CVE-2022-25243 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2189514 Issue Tracking
- https://discuss.hashicorp.com x_refsource_MISCVendor Advisory
- https://discuss.hashicorp.com/t/hcsec-2022-09-vault-pki-secrets-engine-policy-results-in-incorrect-wildcard-certificate-issuance/36600 x_refsource_MISCMitigationVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-29940 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-25243
- https://security.gentoo.org/glsa/202207-01 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-25243
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-25243 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2189514 | Issue Tracking | |
| https://discuss.hashicorp.com | x_refsource_MISCVendor Advisory | |
| https://discuss.hashicorp.com/t/hcsec-2022-09-vault-pki-secrets-engine-policy-results-in-incorrect-wildcard-certificate-issuance/36600 | x_refsource_MISCMitigationVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-29940 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-25243 | ||
| https://security.gentoo.org/glsa/202207-01 | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-25243 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data