{"id":"CVE-2022-36129","details":"HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that could be abused to override the voter status of a node within a Vault HA cluster, introducing potential for future data loss or catastrophic failure. Fixed in Vault Enterprise 1.9.8, 1.10.5, and 1.11.1.","aliases":["BIT-vault-2022-36129"],"modified":"2026-08-12T03:51:11.679164098Z","published":"2022-07-26T22:21:51Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/36xxx/CVE-2022-36129.json","unresolved_ranges":[{"extracted_events":[{"introduced":"1.7.0"},{"fixed":"1.9.7"}],"source":"DESCRIPTION"}],"cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://discuss.hashicorp.com"},{"type":"WEB","url":"https://discuss.hashicorp.com/t/hcsec-2022-15-vault-enterprise-does-not-verify-existing-voter-status-when-joining-an-integrated-storage-ha-node/42420"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/36xxx/CVE-2022-36129.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-36129"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20220901-0011/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hashicorp/vault","events":[{"introduced":"4e222b85c40a810b74400ee3c54449479e32bb9f"},{"last_affected":"b6ba9e768394b97b187e6b0b4bb7b28251e5f030"},{"introduced":"7738ec5d0d6f5bf94a809ee0f6ff0142cfa525a6"},{"last_affected":"6a1dde56c18c4a1be2756b931ce3c872d8ca5a76"},{"introduced":"ea296ccf58507b25051bc0597379c467046eb2f1"},{"last_affected":"ea296ccf58507b25051bc0597379c467046eb2f1"}],"database_specific":{"extracted_events":[{"introduced":"1.7.0"},{"last_affected":"1.9.7"},{"introduced":"1.10.0"},{"last_affected":"1.10.4"},{"introduced":"1.11.0"},{"last_affected":"1.11.0"}],"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:hashicorp:vault:*:*:*:*:*:*:*:*","cpe:2.3:a:hashicorp:vault:1.11.0:*:*:*:-:*:*:*","cpe:2.3:a:hashicorp:vault:1.11.0:*:*:*:enterprise:*:*:*"]}}],"versions":["1.11.0","v1.11.0","v1.10.4","v1.10.3","v1.10.2","v1.10.1","v1.10.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-36129.json"}}],"schema_version":"1.9.0"}