First published: Fri Aug 13 2021(Updated: )
HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser. Fixed in 1.8.0 and pending 1.7.4 / 1.6.6 releases.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Vault | <1.8.0 | |
HashiCorp Vault | <1.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-38554.
The severity of CVE-2021-38554 is medium.
The affected software for CVE-2021-38554 is HashiCorp Vault and Vault Enterprise.
CVE-2021-38554 erroneously caches and exposes user-viewed secrets between sessions in a single shared browser.
CVE-2021-38554 is fixed in version 1.8.0 of HashiCorp Vault, and pending releases 1.7.4 and 1.6.6.