CVE-2020-35177: Infoleak
Published Dec 17, 2020
·Updated
HashiCorp Vault and Vault Enterprise 1.4.1 and newer allowed the enumeration of users via the LDAP auth method. Fixed in 1.5.6 and 1.6.1.
Other sources
HashiCorp Vault and Vault Enterprise allowed the enumeration of users via the LDAP auth method. Fixed in 1.5.6 and 1.6.1.
— GitHub
Affected Software
6 affected componentsFixes available
HashiCorp Vault>=1.5.0<1.5.6
HashiCorp Vault>=1.5.0<1.5.6
HashiCorp Vault>=1.6.0<1.6.1
HashiCorp Vault>=1.6.0<1.6.1
go/github.com/hashicorp/vault>=1.6.0<1.6.1
1.6.1
go/github.com/hashicorp/vault>=1.5.0<1.5.6
1.5.6
Event History
Dec 17, 2020
CVE Published
via MITRE·04:17 AM
Data Sourced
via MITRE·04:17 AM
Description
Jan 31, 2024
Advisory Published
via GitHub·11:11 PM
Frequently Asked Questions
1
What is the vulnerability ID for this HashiCorp Vault vulnerability?
The vulnerability ID for this HashiCorp Vault vulnerability is CVE-2020-35177.
2
What is the severity rating of CVE-2020-35177?
CVE-2020-35177 has a severity rating of medium.
3
How does HashiCorp Vault 1.4.1 and newer allow the enumeration of users?
HashiCorp Vault 1.4.1 and newer allow the enumeration of users through the LDAP auth method.
4
Which versions of HashiCorp Vault are affected by CVE-2020-35177?
HashiCorp Vault versions 1.4.1 to 1.5.6 and 1.6.0 to 1.6.1 are affected by CVE-2020-35177.
5
How can I fix the CVE-2020-35177 vulnerability in HashiCorp Vault?
The CVE-2020-35177 vulnerability in HashiCorp Vault can be fixed by updating to version 1.5.6 or 1.6.1.