VDB
Sign up
HIGH8.1

GHSA-9g4h-h484-3578

HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass

Quick fix

GHSA-9g4h-h484-3578 — github.com/hashicorp/vault: upgrade to the fixed version with the command below.

go get github.com/hashicorp/vault@v1.21.0

Details

Vault and Vault Enterprise's ("Vault") AWS Auth method may be susceptible to authentication bypass if the role of the configured bound_principal_iam is the same across AWS accounts, or uses a wildcard. This vulnerability is fixed in Vault Community Edition 1.21.0 and Vault Enterprise 1.21.0, 1.20.5, 1.19.11, and 1.16.27.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/hashicorp/vault
Introduced in: 0.6.0Fixed in: 1.21.0
Fixgo get github.com/hashicorp/vault@v1.21.0

References