First published: Thu Aug 20 2020(Updated: )
HashiCorp vault-ssh-helper (github.com/hashicorp/vault-ssh-helper/helper) up to and including version 0.1.6 incorrectly accepted Vault-issued SSH OTPs for the subnet in which a host's network interface was located, rather than the specific IP address assigned to that interface. Fixed in 0.2.0.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp vault-ssh-helper | <0.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24359 is a vulnerability in HashiCorp vault-ssh-helper up to and including version 0.1.6.
CVE-2020-24359 has a severity value of 7.5 (High).
CVE-2020-24359 allows the incorrect acceptance of Vault-issued SSH OTPs for the subnet instead of the specific IP address assigned to a host's network interface.
CVE-2020-24359 can be fixed by updating to version 0.2.0 of HashiCorp vault-ssh-helper.
More information about CVE-2020-24359 can be found at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-24359), [GitHub Commit](https://github.com/hashicorp/vault-ssh-helper/commit/83effd08cbcbe4b993d776bd9b39465cd9e4603f), [CHANGELOG](https://github.com/hashicorp/vault-ssh-helper/blob/master/CHANGELOG.md#020-august-19-2020).