CVE-2020-10661: Critical severity hashicorp vault vulnerability
HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 may, under certain circumstances, have existing nested-path policies grant access to Namespaces created after-the-fact. Fixed in 1.3.4.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-10661?
CVE-2020-10661 is a vulnerability in HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 that may allow existing nested-path policies to grant access to Namespaces created after-the-fact.
How severe is CVE-2020-10661?
CVE-2020-10661 has a severity rating of 9.1 (critical).
Which software versions are affected by CVE-2020-10661?
HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 are affected by CVE-2020-10661.
How can I fix CVE-2020-10661?
CVE-2020-10661 can be fixed by updating to version 1.3.4 of HashiCorp Vault or Vault Enterprise.
Where can I find more information about CVE-2020-10661?
More information about CVE-2020-10661 can be found on the official HashiCorp Vault GitHub repository and the HashiCorp blog.