CVE-2021-3282: Improper Authentication
HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the remove-peer
raft operator command to be executed against DR secondaries without authentication. Fixed in 1.6.2.
References
- discuss.hashicorp.com/t/hcsec-2021-04-vault-enterprise-s-dr-secondaries-allowed-raft-peer-removal-without-authentication/20337
- github.com/advisories/GHSA-rq95-xf66-j689
- github.com/hashicorp/vault/commit/09f9068e22f762da123160233518b440e00bdb3b
- nvd.nist.gov/vuln/detail/CVE-2021-3282
- security.gentoo.org/glsa/202207-01
Detect and mitigate CVE-2021-3282 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →