CVE-2022-40186: HashiCorp Vault vulnerable to incorrect metadata access
9.1
CVSS Score
3.1
Basic Information
CVE ID
GHSA ID
EPSS Score
0.48169%
CWE
-
Published
9/23/2022
Updated
2/3/2023
KEV Status
No
Technology
Go
Technical Details
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/hashicorp/vault | go | >= 1.11.0, < 1.11.3 | 1.11.3 |
| github.com/hashicorp/vault | go | >= 1.10.0, < 1.10.6 | 1.10.6 |
| github.com/hashicorp/vault | go | >= 1.8.0, < 1.9.9 | 1.9.9 |