vaultGHSA-m979-w9wj-qfj9
HashiCorp Vault Improper Privilege Management
Medium5.3CVE-2020-10660 · Published Jan 30, 2024 · updated Sep 16, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/vault Go | >= 0.9.0, < 1.3.4 | 1.3.4 |
Details and references
HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Group membership inadvertently include Groups the Entity no longer has permissions to. Fixed in 1.3.4.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-269
- Also known as
- BIT-vault-2020-10660, CVE-2020-10660, GO-2024-2486
More vault advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jan 302024 | HashiCorp Vault Improper Privilege Management CVE-2020-10661Critical9.1fixed in 1.3.4 | Critical9.1 | 1.3.4 |
| Jan 312024 | HashiCorp Vault Authentication bypass CVE-2020-16251High8.2fixed in 1.2.5, 1.3.8, 1.4.4, 1.5.1 | High8.2 | 1.2.5, 1.3.8, 1.4.4, 1.5.1 |
| Jan 312024 | Enumeration of users in HashiCorp Vault CVE-2020-35177Medium6.5fixed in 1.5.6, 1.6.1 | Medium6.5 | 1.5.6, 1.6.1 |
| Jan 312024 | Improper Authentication in HashiCorp Vault CVE-2021-3282High7.5fixed in 1.6.2 | High7.5 | 1.6.2 |
| Feb 12024 | Hashicorp Vault may expose sensitive log information CVE-2024-0831Medium4.5fixed in 1.15.5 | Medium4.5 | 1.15.5 |
| Mar 42024 | Incorrect TLS certificate auth method in Vault CVE-2024-2048High8.1fixed in 1.14.10, 1.15.5 | High8.1 | 1.14.10, 1.15.5 |