Skip to content
vaultGHSA-rq95-xf66-j689

Improper Authentication in HashiCorp Vault

High7.5CVE-2021-3282 · Published Jan 31, 2024 · updated Jun 28, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/vault
Go
>= 1.6.0, < 1.6.21.6.2
Details and references

HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the `remove-peer` raft operator command to be executed against DR secondaries without authentication. Fixed in 1.6.2.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-287
Also known as
BIT-vault-2021-3282, CVE-2021-3282, GO-2024-2509

More vault advisories

All
DateAdvisory
Jan 302024HashiCorp Vault Improper Privilege Management
CVE-2020-10660Medium5.3fixed in 1.3.4
Jan 302024HashiCorp Vault Improper Privilege Management
CVE-2020-10661Critical9.1fixed in 1.3.4
Jan 312024HashiCorp Vault Authentication bypass
CVE-2020-16251High8.2fixed in 1.2.5, 1.3.8, 1.4.4, 1.5.1
Jan 312024Enumeration of users in HashiCorp Vault
CVE-2020-35177Medium6.5fixed in 1.5.6, 1.6.1
Feb 12024Hashicorp Vault may expose sensitive log information
CVE-2024-0831Medium4.5fixed in 1.15.5
Mar 42024Incorrect TLS certificate auth method in Vault
CVE-2024-2048High8.1fixed in 1.14.10, 1.15.5

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.