First published: Mon Mar 23 2020(Updated: )
HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Group membership inadvertently include Groups the Entity no longer has permissions to. Fixed in 1.3.4.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Vault | >=0.9.0<=1.3.3 | |
HashiCorp Vault | >=0.9.0<=1.3.3 | |
go/github.com/hashicorp/vault | >=0.9.0<1.3.4 | 1.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-10660.
CVE-2020-10660 has a severity level of medium with a score of 5.3.
HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 are affected by CVE-2020-10660.
To check if your version of HashiCorp Vault is affected by CVE-2020-10660, check the version number against the affected versions (0.9.0 through 1.3.3).
To fix CVE-2020-10660, upgrade to version 1.3.4 or later of HashiCorp Vault or Vault Enterprise.