First published: Thu Dec 17 2020(Updated: )
HashiCorp Vault and Vault Enterprise 1.4.1 and newer allowed the enumeration of users via the LDAP auth method. Fixed in 1.5.6 and 1.6.1.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Vault | >=1.5.0<1.5.6 | |
HashiCorp Vault | >=1.5.0<1.5.6 | |
HashiCorp Vault | >=1.6.0<1.6.1 | |
HashiCorp Vault | >=1.6.0<1.6.1 | |
go/github.com/hashicorp/vault | >=1.6.0<1.6.1 | 1.6.1 |
go/github.com/hashicorp/vault | >=1.5.0<1.5.6 | 1.5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this HashiCorp Vault vulnerability is CVE-2020-35177.
CVE-2020-35177 has a severity rating of medium.
HashiCorp Vault 1.4.1 and newer allow the enumeration of users through the LDAP auth method.
HashiCorp Vault versions 1.4.1 to 1.5.6 and 1.6.0 to 1.6.1 are affected by CVE-2020-35177.
The CVE-2020-35177 vulnerability in HashiCorp Vault can be fixed by updating to version 1.5.6 or 1.6.1.