CVE-2020-35192: Critical severity hashicorp vault vulnerability
Published Dec 17, 2020
·Updated
The official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
Affected Software
1 affected component
HashiCorp Vault>=0.6.0<0.11.6
Event History
Dec 17, 2020
CVE Published
via MITRE·01:33 AM
Data Sourced
via MITRE·01:33 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-35192.
2
What is the severity of CVE-2020-35192?
The severity of CVE-2020-35192 is critical with a score of 9.8.
3
What is the affected software?
The affected software is HashiCorp Vault version 0.6.0 to 0.11.6.
4
How can a remote attacker exploit CVE-2020-35192?
A remote attacker can exploit CVE-2020-35192 by using a blank password for the root user in a Vault Docker container.
5
How can I fix CVE-2020-35192?
To fix CVE-2020-35192, update to a version of the Vault Docker image that is later than 0.11.6.