CVE-2021-38554: Medium severity HashiCorp Vault vulnerability
HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser. Fixed in 1.8.0 and pending 1.7.4 / 1.6.6 releases.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HashiCorp Vault and Vault Enterpriseto a version that resolves this vulnerability.Fixed in 1.8.0 - Upgrade
Upgrade
HashiCorp Vault and Vault Enterpriseto a version that resolves this vulnerability.Fixed in 1.7.4 - Upgrade
Upgrade
HashiCorp Vault and Vault Enterpriseto a version that resolves this vulnerability.Fixed in 1.6.6
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-38554.
What is the severity of CVE-2021-38554?
The severity of CVE-2021-38554 is medium.
What is the affected software for CVE-2021-38554?
The affected software for CVE-2021-38554 is HashiCorp Vault and Vault Enterprise.
How does CVE-2021-38554 impact users?
CVE-2021-38554 erroneously caches and exposes user-viewed secrets between sessions in a single shared browser.
What is the fix for CVE-2021-38554?
CVE-2021-38554 is fixed in version 1.8.0 of HashiCorp Vault, and pending releases 1.7.4 and 1.6.6.