CVE-2024-7594 describes a critical vulnerability in HashiCorp Vault and OpenBao's SSH secrets engine. If the valid_principals and default_user fields are not explicitly configured, an authorized user can request an SSH certificate that allows authentication as any user on a host, bypassing intended access controls. This high-severity flaw (CVSS 8.8) has a low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. While no active exploitation, public exploits, or significant community discussion have been observed, affected organizations should prioritize patching to Vault Community Edition 1.17.6 or Vault Enterprise 1.17.6, 1.16.10, or 1.15.15.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.7.7, < 1.15.15CPE matchmatch criteria | cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* | ||
>= 1.7.7, < 1.17.6CPE matchmatch criteria | cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:* | ||
>= 1.16.0, < 1.16.10CPE matchmatch criteria | cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* | ||
>= 1.17.0, < 1.17.6CPE matchmatch criteria | cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* | ||
< 2.0.2CPE matchmatch criteria | cpe:2.3:a:openbao:openbao:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.