CVE-2022-30689
HashiCorp Vault and Vault Enterprise from 1.10.0 to 1.10.2 did not correctly configure and enforce MFA on login after server restarts. This affects the Login MFA feature introduced in Vault and Vault Enterprise 1.10.0 and does not affect the separate Enterprise MFA feature set. Fixed in 1.10.3.
- Affected products
- Hashicorp Vault, Vault Enterprise
- Hashicorp Vault
- < 1.10.3
- Fix
- Available
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 1.1% (63th percentile)
- NVD status
- Modified
- Published
- 2022-05-17
CVE-2022-30689 at NVD
No indexed exploits for CVE-2022-30689 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2022-30689 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.