CVE-2022-25243
"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates to authorized users for a specified domain, even if the PKI role policy attribute allow_subdomains is set to false. Fixed in Vault Enterprise 1.8.9 and 1.9.4.
- Affected products
- Vault, Vault Enterprise
- Hashicorp Vault
- < 1.8.9, 1.9.4
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.6% (44th percentile)
- Weakness
- CWE-295
- NVD status
- Modified
- Published
- 2022-03-07
CVE-2022-25243 at NVD
No indexed exploits for CVE-2022-25243 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2022-25243 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.