First published: Mon Mar 23 2020(Updated: )
HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 may, under certain circumstances, have existing nested-path policies grant access to Namespaces created after-the-fact. Fixed in 1.3.4.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Vault | >=0.11.0<=1.3.3 | |
HashiCorp Vault | >=0.11.0<=1.3.3 | |
go/github.com/hashicorp/vault | >=0.11.0<1.3.4 | 1.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10661 is a vulnerability in HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 that may allow existing nested-path policies to grant access to Namespaces created after-the-fact.
CVE-2020-10661 has a severity rating of 9.1 (critical).
HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 are affected by CVE-2020-10661.
CVE-2020-10661 can be fixed by updating to version 1.3.4 of HashiCorp Vault or Vault Enterprise.
More information about CVE-2020-10661 can be found on the official HashiCorp Vault GitHub repository and the HashiCorp blog.