Vulnerability Description
Vault and Vault Enterprise did not properly validate the JSON Web Token (JWT) role-bound audience claim when using the Vault JWT auth method. This may have resulted in Vault validating a JWT the audience and role-bound claims do not match, allowing an invalid login to succeed when it should have been rejected. This vulnerability, CVE-2024-5798, was fixed in Vault and Vault Enterprise 1.17.0, 1.16.3, and 1.15.9
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hashicorp | Vault | >= 0.11.0, < 1.15.9 |
Related Weaknesses (CWE)
References
- https://discuss.hashicorp.com/t/hcsec-2024-11-vault-incorrectly-validated-json-wVendor Advisory
- https://discuss.hashicorp.com/t/hcsec-2024-11-vault-incorrectly-validated-json-wVendor Advisory
FAQ
What is CVE-2024-5798?
CVE-2024-5798 is a vulnerability with a CVSS score of 2.6 (LOW). Vault and Vault Enterprise did not properly validate the JSON Web Token (JWT) role-bound audience claim when using the Vault JWT auth method. This may have resulted in Vault validating a JWT the audie...
How severe is CVE-2024-5798?
CVE-2024-5798 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-5798?
Check the references section above for vendor advisories and patch information. Affected products include: Hashicorp Vault.