Miggo Logo

CVE-2024-2660: HashiCorpVault does not correctly validate OCSP responses

6.4

CVSS Score
3.1

Basic Information

EPSS Score
0.05268%
Published
4/4/2024
Updated
9/26/2024
KEV Status
No
Technology
TechnologyGo

Technical Details

CVSS Vector
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
github.com/hashicorp/vaultgo< 1.16.01.16.0

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

V*ult *n* V*ult *nt*rpris* TLS **rti*i**t*s *ut* m*t*o* *i* not *orr**tly v*li**t* O*SP r*spons*s w**n on* or mor* O*SP sour**s w*r* *on*i*ur**. *ix** in V*ult *.**.* *n* V*ult *nt*rpris* *.**.*, *.**.*, *n* *.**.**.

Reasoning

No *n*lysis *v*il**l*