VaultGHSA-4mp7-2m29-gqxf
HashiCorp Vault Authentication bypass
High8.2CVE-2020-16251 · Published Jan 31, 2024 · updated Sep 16, 2024
HashiCorp Vault and Vault Enterprise versions 0.8.3 and newer, when configured with the GCP GCE auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/vault Go | >= 0.8.3, < 1.2.5 | 1.2.5 |
| >= 1.3.0, < 1.3.8 | 1.3.8 | |
| >= 1.4.0, < 1.4.4 | 1.4.4 | |
| >= 1.5.0, < 1.5.1 | 1.5.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-287
- Also known as
- BIT-vault-2020-16251, CVE-2020-16251, GO-2024-2488
More Vault advisories
All Vault| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 42024 | Incorrect TLS certificate auth method in Vault | High8.1 | 1.14.10+1 more |
| Feb 12024 | Hashicorp Vault may expose sensitive log information | Medium4.5 | 1.15.5 |
| Jan 312024 | Improper Authentication in HashiCorp Vault | High7.5 | 1.6.2 |
| Jan 312024 | Enumeration of users in HashiCorp Vault | Medium6.5 | 1.5.6+1 more |
| Jan 302024 | HashiCorp Vault Improper Privilege Management | Medium5.3 | 1.3.4 |
| Jan 302024 | HashiCorp Vault Improper Privilege Management | Critical9.1 | 1.3.4 |