Skip to main content

Improper Check or Handling of Exceptional Conditions

CVE-2024-2660

Severity Medium
Score 6.4/10

Summary

Vault and Vault Enterprise TLS certificates auth method did not correctly validate OCSP responses when one or more OCSP sources were configured. Affected version in Vault are through 1.14.10, and 1.15.0-rc1 through v1.15.6.

  • HIGH
  • ADJACENT_NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • HIGH
  • HIGH
  • HIGH

CWE-703 - Improper Check or Handling of Exceptional Conditions

The software does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the software.

Advisory Timeline

  • Published