VaultGHSA-9vh5-r4qw-v3vv
Improper Resource Shutdown or Release in HashiCorp Vault
High7.5CVE-2020-7220 · Published Jul 28, 2021 · updated Aug 21, 2024
HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails, in certain circumstances, to revoke dynamic secrets for a mount in a deleted namespace. Fixed in 1.3.2.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/vault Go | >= 0.11.0, < 1.3.2 | 1.3.2 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-404
- Also known as
- BIT-vault-2020-7220, CVE-2020-7220, GO-2022-0816
More Vault advisories
All Vault| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 122021 | Hashicorp Vault Privilege Escalation Vulnerability | Low2.9 | 1.7.5+1 more |
| Aug 302021 | HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0 | Critical9.8 | 1.8.0 |
| Aug 302021 | Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault | Medium5.3 | 1.6.6+1 more |
| Aug 22021 | Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault | High8.2 | 1.2.5+3 more |
| Jun 82021 | Invalid session token expiration | High7.4 | 1.5.9+2 more |
| May 182021 | Information Disclosure in HashiCorp Vault | High7.5 | 1.3.6+1 more |