CVE-2020-10661

HashiCorp Vault Improper Privilege Management in go/github.com/hashicorp/vault/vault

Identifiers

GHSA-j6vv-vv26-rh7c, CVE-2020-10661

Package Slug

go/github.com/hashicorp/vault/vault

Vulnerability

HashiCorp Vault Improper Privilege Management

Description

HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 may, under certain circumstances, have existing nested-path policies grant access to Namespaces created after-the-fact. Fixed in 1.3.4.

Affected Versions

All versions starting from 0.11.0 before 1.3.4

Solution

Upgrade to version 1.3.4 or above.

Last Modified

2024-01-31

source