REDHAT-BUG-2459107: High severity HashiCorp Vault vulnerability
If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.21.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.20.10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.19.16
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2459107?
The severity of REDHAT-BUG-2459107 is rated as high, with a score of 7.
How do I fix REDHAT-BUG-2459107?
To fix REDHAT-BUG-2459107, update HashiCorp Vault to versions 2.0.0, 1.21.5, 1.20.10, or 1.19.16.
What does REDHAT-BUG-2459107 affect?
REDHAT-BUG-2459107 affects the configuration of Vault auth mounts configured to pass through the 'Authorization' header.
What risk does REDHAT-BUG-2459107 pose?
REDHAT-BUG-2459107 poses a risk of exposing Vault tokens to the auth plugin backend when the 'Authorization' header is used.
When was REDHAT-BUG-2459107 published?
REDHAT-BUG-2459107 was published on April 17, 2026.