VaultGHSA-23fq-q7hc-993r
HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0
Critical9.8CVE-2021-38553 · Published Aug 30, 2021 · updated Aug 21, 2024
HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/vault Go | >= 1.4.0, < 1.8.0 | 1.8.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-281
- Also known as
- BIT-vault-2021-38553, CVE-2021-38553, GO-2022-0620
More Vault advisories
All Vault| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 122021 | Incorrect Privilege Assignment in HashiCorp Vault | High8.1 | No fix yet |
| Oct 122021 | Hashicorp Vault Privilege Escalation Vulnerability | Low2.9 | 1.7.5+1 more |
| Aug 302021 | Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault | Medium5.3 | 1.6.6+1 more |
| Aug 22021 | Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault | High8.2 | 1.2.5+3 more |
| Jul 282021 | Improper Resource Shutdown or Release in HashiCorp Vault | High7.5 | 1.3.2 |
| Jun 82021 | Invalid session token expiration | High7.4 | 1.5.9+2 more |