CVE-2021-3024: Medium severity HashiCorp Vault vulnerability
HashiCorp Vault and Vault Enterprise disclosed the internal IP address of the Vault node when responding to some invalid, unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HashiCorp Vault / Vault Enterpriseto a version that resolves this vulnerability.Fixed in 1.6.2 - Upgrade
Upgrade
HashiCorp Vault / Vault Enterpriseto a version that resolves this vulnerability.Fixed in 1.5.7
Event History
Frequently Asked Questions
What is the vulnerability ID for this HashiCorp Vault vulnerability?
The vulnerability ID for this HashiCorp Vault vulnerability is CVE-2021-3024.
What is the severity of CVE-2021-3024?
The severity of CVE-2021-3024 is medium with a CVSS score of 5.3.
What is the affected software?
The affected software includes HashiCorp Vault versions up to 1.5.7 and versions between 1.6.0 and 1.6.2, both Vault and Vault Enterprise editions.
How can I fix CVE-2021-3024 vulnerability?
The CVE-2021-3024 vulnerability can be fixed by updating HashiCorp Vault to version 1.6.2 or 1.5.7.
Where can I find more information about CVE-2021-3024?
More information about CVE-2021-3024 can be found in the following references: [link1](https://discuss.hashicorp.com/t/hcsec-2021-02-vault-api-endpoint-exposed-internal-ip-address-without-authentication/20334), [link2](https://security.gentoo.org/glsa/202207-01).