VaultGHSA-25xj-89g5-fm6h
Information Disclosure in HashiCorp Vault
High7.5CVE-2020-13223 · Published May 18, 2021 · updated Aug 21, 2024
HashiCorp Vault and Vault Enterprise before 1.3.6, and 1.4.2 before 1.4.2, insert Sensitive Information into a Log File. The vulnerability is affecting `github.com/hashicorp/vault/command` Go package.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/vault Go | >= 1.3.0, < 1.3.6 | 1.3.6 |
| >= 1.4.0, < 1.4.2 | 1.4.2 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-200, CWE-532
- Also known as
- BIT-vault-2020-13223, CVE-2020-13223, GO-2022-0778
- nvd.nist.gov/vuln/detail/CVE-2020-13223
- github.com/hashicorp/vault/commit/87f47c216cf1a28f4054b80cff40de8c9e00e36c
- github.com/hashicorp/vault/commit/e52f34772affb69f3239b2cdf6523cb7cfd67a92
- github.com/hashicorp/vault
- github.com/hashicorp/vault/blob/master/CHANGELOG.md#142-may-21st-2020
- www.hashicorp.com/blog/category/vault
More Vault advisories
All Vault| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 122021 | Hashicorp Vault Privilege Escalation Vulnerability | Low2.9 | 1.7.5+1 more |
| Aug 302021 | HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0 | Critical9.8 | 1.8.0 |
| Aug 302021 | Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault | Medium5.3 | 1.6.6+1 more |
| Aug 22021 | Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault | High8.2 | 1.2.5+3 more |
| Jul 282021 | Improper Resource Shutdown or Release in HashiCorp Vault | High7.5 | 1.3.2 |
| Jun 82021 | Invalid session token expiration | High7.4 | 1.5.9+2 more |