CVE-2020-25594: Medium severity hashicorp vault vulnerability
HashiCorp Vault and Vault Enterprise allowed for enumeration of Secrets Engine mount paths via unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-25594?
CVE-2020-25594 is a vulnerability in HashiCorp Vault and Vault Enterprise that allowed for enumeration of Secrets Engine mount paths via unauthenticated HTTP requests.
What is the severity of CVE-2020-25594?
The severity of CVE-2020-25594 is medium, with a severity value of 5.3.
How can I fix CVE-2020-25594?
To fix CVE-2020-25594, you need to upgrade to HashiCorp Vault version 1.6.2 or 1.5.7.
Where can I find more information about CVE-2020-25594?
You can find more information about CVE-2020-25594 in the following references: [link1](https://discuss.hashicorp.com/t/hcsec-2021-03-vault-api-endpoint-allowed-enumeration-of-secrets-engine-mount-paths-without-authentication/20336), [link2](https://security.gentoo.org/glsa/202207-01).