hashicorp vault CVE-2021-45042 is a vulnerability in HashiCorp Vault
Published on December 17, 2021

In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.

Vendor Advisory NVD


Products Associated with CVE-2021-45042

Want to know whenever a new CVE is published for HashiCorp Vault? stack.watch will email you.

 

Exploit Probability

EPSS
0.43%
Percentile
62.53%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.