GHSA-57gg-cj55-q5g2, CVE-2020-25816
go/github.com/hashicorp/vault
Token leases could outlive their TTL in HashiCorp Vault
HashiCorp Vault and Vault Enterprise versions 1.0 and newer allowed leases created with a batch token to outlive their TTL because expiration time was not scheduled correctly. Fixed in 1.4.7 and 1.5.4.
All versions starting from 1.0 before 1.5.4
Upgrade to version 1.5.4 or above.
2024-02-02
source |