CVE-2021-3282: High severity HashiCorp Vault vulnerability
HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the remove-peer raft operator command to be executed against DR secondaries without authentication. Fixed in 1.6.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/hashicorp/vaultto a version that resolves this vulnerability.Fixed in 1.6.2 - Upgrade
Upgrade
HashiCorp Vault Enterpriseto a version that resolves this vulnerability.Fixed in 1.6.2
Event History
Frequently Asked Questions
What is the vulnerability ID of this HashiCorp Vault Enterprise vulnerability?
The vulnerability ID of this HashiCorp Vault Enterprise vulnerability is CVE-2021-3282.
What is the severity of CVE-2021-3282?
The severity of CVE-2021-3282 is high.
Which versions of HashiCorp Vault Enterprise are affected by CVE-2021-3282?
CVE-2021-3282 affects HashiCorp Vault Enterprise 1.6.0 and 1.6.1.
How can the vulnerability CVE-2021-3282 be fixed?
To fix CVE-2021-3282, upgrade HashiCorp Vault Enterprise to version 1.6.2 or higher.
Is there any additional information available about CVE-2021-3282?
Yes, you can find additional information about CVE-2021-3282 at the following references: [Reference 1](https://discuss.hashicorp.com/t/hcsec-2021-04-vault-enterprise-s-dr-secondaries-allowed-raft-peer-removal-without-authentication/20337) and [Reference 2](https://security.gentoo.org/glsa/202207-01).