This vulnerability, CVE-2024-5798, was fixed in Vault and Vault Enterprise 1.17.0, 1.16.3, and 1.15.9
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1892 | Vault and Vault Enterprise did not properly validate the JSON Web Token (JWT) role-bound audience claim when using the Vault JWT auth method. This may have resulted in Vault validating a JWT the audience and role-bound claims do not match, allowing an invalid login to succeed when it should have been rejected. This vulnerability, CVE-2024-5798, was fixed in Vault and Vault Enterprise 1.17.0, 1.16.3, and 1.15.9 |
Github GHSA |
GHSA-32cj-5wx4-gq8p | HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims |
Tue, 04 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Nov 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 |
Thu, 07 Aug 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:* cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* |
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2025-11-04T16:30:51.697Z
Reserved: 2024-06-10T15:46:30.387Z
Link: CVE-2024-5798
Updated: 2024-08-01T21:25:02.659Z
Status : Modified
Published: 2024-06-12T19:15:51.413
Modified: 2025-11-04T17:16:15.977
Link: CVE-2024-5798
OpenCVE Enrichment
Updated: 2025-07-12T22:00:58Z
EUVD
Github GHSA