HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not validate TLS certificates when connecting to Cassandra clusters. Fixed in 1.6.4 and 1.7.1
{ "cpes": [ "cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*", "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*" ], "severity": "High" }