Miggo Logo

CVE-2022-40186: HashiCorp Vault vulnerable to incorrect metadata access

9.1

CVSS Score
3.1

Basic Information

EPSS Score
0.48169%
CWE
-
Published
9/23/2022
Updated
2/3/2023
KEV Status
No
Technology
TechnologyGo

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
github.com/hashicorp/vaultgo>= 1.11.0, < 1.11.31.11.3
github.com/hashicorp/vaultgo>= 1.10.0, < 1.10.61.10.6
github.com/hashicorp/vaultgo>= 1.8.0, < 1.9.91.9.9

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

*n issu* w*s *is*ov*r** in **s*i*orp V*ult *n* V*ult *nt*rpris* ***or* *.**.*. * vuln*r**ility in t** I**ntity *n*in* w*s *oun* w**r*, in * **ploym*nt w**r* *n *ntity **s multipl* mount ****ssors wit* s**r** *li*s n*m*s, V*ult m*y ov*rwrit* m*t***t*

Reasoning

No *n*lysis *v*il**l*