Skip to content
vaultGHSA-57gg-cj55-q5g2

Token leases could outlive their TTL in HashiCorp Vault

Critical9.8CVE-2020-25816 · Published May 24, 2022 · updated Feb 3, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/vault
Go
>= 1.0.0-beta1, < 1.5.41.5.4
Details and references

HashiCorp Vault and Vault Enterprise 1.0 before 1.5.4 have Incorrect Access Control.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-613
Also known as
BIT-vault-2020-25816, CVE-2020-25816, GO-2024-2514

More vault advisories

All
DateAdvisory
May 182022HashiCorp Vault improper configuration of multi factor authentication
CVE-2022-30689Medium5.3fixed in 1.10.3
Sep 232022HashiCorp Vault vulnerable to incorrect metadata access
CVE-2022-40186Critical9.1fixed in 1.9.9, 1.10.6, 1.11.3
Dec 22021HashiCorp Vault Incorrect Permission Assignment for Critical Resource
CVE-2021-43998Critical9.1fixed in 1.7.6, 1.8.5
Oct 122021Incorrect Privilege Assignment in HashiCorp Vault
CVE-2021-42135High8.1no fix yet
Oct 122021Hashicorp Vault Privilege Escalation Vulnerability
CVE-2021-41802Low2.9fixed in 1.7.5, 1.8.4
Aug 302021HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0
CVE-2021-38553Critical9.8fixed in 1.8.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.