vaultGHSA-fp52-qw33-mfmw
Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault
High8.2CVE-2020-16250 · Published Aug 2, 2021 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/vault Go | >= 0.8.1, < 1.2.5 | 1.2.5 |
| >= 1.3.0, < 1.3.8 | 1.3.8 | |
| >= 1.4.0, < 1.4.4 | 1.4.4 | |
| >= 1.5.0, < 1.5.1 | 1.5.1 |
Details and references
HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured with the AWS IAM auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1..
More vault advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 282021 | Improper Resource Shutdown or Release in HashiCorp Vault CVE-2020-7220High7.5fixed in 1.3.2 | High7.5 | 1.3.2 |
| Aug 302021 | Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault CVE-2021-38554Medium5.3fixed in 1.6.6, 1.7.4 | Medium5.3 | 1.6.6, 1.7.4 |
| Aug 302021 | HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0 CVE-2021-38553Critical9.8fixed in 1.8.0 | Critical9.8 | 1.8.0 |
| Jun 82021 | Invalid session token expiration CVE-2021-32923High7.4fixed in 1.5.9, 1.6.5, 1.7.2 | High7.4 | 1.5.9, 1.6.5, 1.7.2 |
| Oct 122021 | Hashicorp Vault Privilege Escalation Vulnerability CVE-2021-41802Low2.9fixed in 1.7.5, 1.8.4 | Low2.9 | 1.7.5, 1.8.4 |
| Oct 122021 | Incorrect Privilege Assignment in HashiCorp Vault CVE-2021-42135High8.1no fix yet | High8.1 | No fix yet |