Sploitus

CVE-2022-25243

No indexed exploits for CVE-2022-25243 yet

"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates to authorized users for a specified domain, even if the PKI role policy attribute allow_subdomains is set to false. Fixed in Vault Enterprise 1.8.9 and 1.9.4.

Affected products
Vault, Vault Enterprise
Hashicorp Vault
< 1.8.9, 1.9.4
Fix
Available
CVSS 3.1
6.5 MEDIUM
EPSS
0.6% (44th percentile)
Weakness
CWE-295
NVD status
Modified
Published
2022-03-07
CVE-2022-25243 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2022-25243 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2022-25243 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.