CVE-2020-25816

Token leases could outlive their TTL in HashiCorp Vault in go/github.com/hashicorp/vault

Identifiers

GHSA-57gg-cj55-q5g2, CVE-2020-25816

Package Slug

go/github.com/hashicorp/vault

Vulnerability

Token leases could outlive their TTL in HashiCorp Vault

Description

HashiCorp Vault and Vault Enterprise versions 1.0 and newer allowed leases created with a batch token to outlive their TTL because expiration time was not scheduled correctly. Fixed in 1.4.7 and 1.5.4.

Affected Versions

All versions starting from 1.0 before 1.5.4

Solution

Upgrade to version 1.5.4 or above.

Last Modified

2024-02-02

source