CVE-2022-40186
An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may allow for unintended access to key/value paths using that metadata in Vault.
- Affected products
- Hashicorp Vault, Hashicorp Vault Enterprise, Red Os
- Hashicorp Vault
- < 1.9.9, 1.10.6, 1.11.3
- Fix
- Available
- CVSS 3.1
- 9.1 CRITICAL
- EPSS
- 0.8% (53th percentile)
- Weakness
- CWE-639
- NVD status
- Modified
- Published
- 2022-09-22
CVE-2022-40186 at NVD
No indexed exploits for CVE-2022-40186 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2022-40186 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.