Threats Tagged 'bit-vault-2024-7594'
View all threats tagged with 'bit-vault-2024-7594'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'bit-vault-2024-7594'
Click on any threat for detailed analysis and mitigation recommendations
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default (CVE-2024-7594)CVE-2024-7594 0 Vault's SSH secrets engine had a configuration issue where the valid_principals list was not required to contain a value by default. This could allow an authorized user to request an SSH certificate that authenticates as any user on the host if the valid_principals and default_user fields were not set. The vulnerability affects Vault Community Edition and Enterprise versions prior to 1.17.6 and has been fixed in versions 1.17.6 (Community), 1.17.6, 1.16.10, and 1.15.15 (Enterprise). Join the discussion | GCVE Database | 07/27/2026, 05:48:43 UTC Added: 09/08/2026, 12:55:13 UTC |
Showing 1 to 1 of 1 result