HIGH7.4
GHSA-38j9-7pp9-2hjw
Invalid session token expiration
Quick fix
GHSA-38j9-7pp9-2hjw — github.com/hashicorp/vault: upgrade to the fixed version with the command below.
go get github.com/hashicorp/vault@v1.7.2Details
HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/vault
Introduced in:
1.7.0Fixed in: 1.7.2Fix
go get github.com/hashicorp/vault@v1.7.2Go/github.com/hashicorp/vault
Introduced in:
1.6.0Fixed in: 1.6.5Fix
go get github.com/hashicorp/vault@v1.6.5Go/github.com/hashicorp/vault
Introduced in:
0.10.0Fixed in: 1.5.9Fix
go get github.com/hashicorp/vault@v1.5.9