CVE-2024-5798Low· 2.6▾ SunlitHashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims
▾ Sunlit zone — Low / medium · no exploitation signal
impact 14.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
Vault and Vault Enterprise did not properly validate the JSON Web Token (JWT) role-bound audience claim when using the Vault JWT auth method. This may have resulted in Vault validating a JWT the audience and role-bound claims do not match, allowing an invalid login to succeed when it should have been rejected.
This vulnerability, CVE-2024-5798, was fixed in Vault and Vault Enterprise 1.17.0, 1.16.3, and 1.15.9
github.com/hashicorp/vault >= 1.17.0-rc1, < 1.17.0github.com/hashicorp/vault >= 1.16.0-rc1, < 1.16.3github.com/hashicorp/vault >= 0.11.0, < 1.15.9Upgrade to a patched release:
github.com/hashicorp/vault 1.17.0github.com/hashicorp/vault 1.16.3github.com/hashicorp/vault 1.15.9Connected by shared product, vendor, weakness, or advisory.
CVE-2023-5077High· 7.6Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability
CVE-2025-6013Medium· 6.5HashiCorp Vault ldap auth method may not have correctly enforced MFA
CVE-2025-5999High· 7.2Hashicorp Vault has Privilege Escalation Vulnerability
CVE-2025-6037Medium· 6.8Hashicorp Vault has Incorrect Validation for Non-CA Certificates
CVE-2023-5954High· 7.5HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability
CVE-2024-6468High· 7.5Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions