CVE-2020-7220: High severity HashiCorp Vault vulnerability
HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails, in certain circumstances, to revoke dynamic secrets for a mount in a deleted namespace. Fixed in 1.3.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HashiCorp Vault Enterpriseto a version that resolves this vulnerability.Fixed in 1.3.2
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-7220.
What is the affected software for this vulnerability?
The affected software for this vulnerability is HashiCorp Vault Enterprise versions 0.11.0 through 1.3.1.
What is the severity level of this vulnerability?
The severity level of this vulnerability is high, with a CVSS score of 7.5.
How does this vulnerability manifest?
This vulnerability in HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails to revoke dynamic secrets for a mount in a deleted namespace.
What is the fix for this vulnerability?
This vulnerability is fixed in version 1.3.2 of HashiCorp Vault Enterprise.