Vulnerabilities > CVE-2022-30689 - Unspecified vulnerability in Hashicorp Vault 1.10.0/1.10.2
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
LOW Availability impact
NONE Summary
HashiCorp Vault and Vault Enterprise from 1.10.0 to 1.10.2 did not correctly configure and enforce MFA on login after server restarts. This affects the Login MFA feature introduced in Vault and Vault Enterprise 1.10.0 and does not affect the separate Enterprise MFA feature set. Fixed in 1.10.3.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |