—
GO-2022-1021
HashiCorp Vault vulnerable to incorrect metadata access in github.com/hashicorp/vault
Quick fix
GO-2022-1021 — github.com/hashicorp/vault: upgrade to the fixed version with the command below.
go get github.com/hashicorp/vault@v1.9.9Details
HashiCorp Vault vulnerable to incorrect metadata access in github.com/hashicorp/vault
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/vault
Introduced in:
1.8.0Fixed in: 1.9.9Fix
go get github.com/hashicorp/vault@v1.9.9References
- https://github.com/advisories/GHSA-7cgv-v83v-rr87[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2022-40186[ADVISORY]
- https://discuss.hashicorp.com[WEB]
- https://discuss.hashicorp.com/t/hcsec-2022-18-vault-entity-alias-metadata-may-leak-between-aliases-with-the-same-name-assigned-to-the-same-entity/44550[WEB]
- https://github.com/hashicorp/vault[WEB]
- https://security.netapp.com/advisory/ntap-20221111-0008[WEB]