Security Advisory

CVE-2022-25244

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-03-07 21:41:52
Last updated 2024-08-03 04:36:06
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenization key configuration endpoint to authorized operators with `read` permissions on this endpoint. Fixed in Vault Enterprise 1.9.4, 1.8.9 and 1.7.10.