Skip to content
vaultGHSA-fp52-qw33-mfmw

Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault

High8.2CVE-2020-16250 · Published Aug 2, 2021 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/vault
Go
>= 0.8.1, < 1.2.51.2.5
>= 1.3.0, < 1.3.81.3.8
>= 1.4.0, < 1.4.41.4.4
>= 1.5.0, < 1.5.11.5.1
Details and references

HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured with the AWS IAM auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1..

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-290, CWE-345
Also known as
BIT-vault-2020-16250, CVE-2020-16250, GO-2022-0825

More vault advisories

All
DateAdvisory
Jul 282021Improper Resource Shutdown or Release in HashiCorp Vault
CVE-2020-7220High7.5fixed in 1.3.2
Aug 302021Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault
CVE-2021-38554Medium5.3fixed in 1.6.6, 1.7.4
Aug 302021HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0
CVE-2021-38553Critical9.8fixed in 1.8.0
Jun 82021Invalid session token expiration
CVE-2021-32923High7.4fixed in 1.5.9, 1.6.5, 1.7.2
Oct 122021Hashicorp Vault Privilege Escalation Vulnerability
CVE-2021-41802Low2.9fixed in 1.7.5, 1.8.4
Oct 122021Incorrect Privilege Assignment in HashiCorp Vault
CVE-2021-42135High8.1no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.