CVE-2024-7594

ADVISORY - github

Summary

Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields of the SSH secrets engine configuration are not set, an SSH certificate requested by an authorized user to Vault’s SSH secrets engine could be used to authenticate as any user on the host. Fixed in Vault Community Edition 1.17.6, and in Vault Enterprise 1.17.6, 1.16.10, and 1.15.15.

EPSS Score: 0.00731 (0.724)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Incorrect Permission Assignment for Critical Resource

ADVISORY - github

Incorrect Permission Assignment for Critical Resource

ADVISORY - gitlab

OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities

Incorrect Permission Assignment for Critical Resource

OWASP Top Ten 2013 Category A9 - Using Components with Known Vulnerabilities

ADVISORY - redhat

Incorrect Permission Assignment for Critical Resource


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in