CVE-2020-24359: Input Validation
HashiCorp vault-ssh-helper (github.com/hashicorp/vault-ssh-helper/helper) up to and including version 0.1.6 incorrectly accepted Vault-issued SSH OTPs for the subnet in which a host's network interface was located, rather than the specific IP address assigned to that interface. Fixed in 0.2.0.
Other sources
HashiCorp vault-ssh-helper up to and including version 0.1.6 incorrectly accepted Vault-issued SSH OTPs for the subnet in which a host's network interface was located, rather than the specific IP address assigned to that interface. Fixed in 0.2.0.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-24359?
CVE-2020-24359 is a vulnerability in HashiCorp vault-ssh-helper up to and including version 0.1.6.
What is the severity of CVE-2020-24359?
CVE-2020-24359 has a severity value of 7.5 (High).
How does CVE-2020-24359 affect HashiCorp vault-ssh-helper?
CVE-2020-24359 allows the incorrect acceptance of Vault-issued SSH OTPs for the subnet instead of the specific IP address assigned to a host's network interface.
How can CVE-2020-24359 be fixed?
CVE-2020-24359 can be fixed by updating to version 0.2.0 of HashiCorp vault-ssh-helper.
Where can I find more information about CVE-2020-24359?
More information about CVE-2020-24359 can be found at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-24359), [GitHub Commit](https://github.com/hashicorp/vault-ssh-helper/commit/83effd08cbcbe4b993d776bd9b39465cd9e4603f), [CHANGELOG](https://github.com/hashicorp/vault-ssh-helper/blob/master/CHANGELOG.md#020-august-19-2020).