VDB
Sign up
HIGH8.2

GHSA-fp52-qw33-mfmw

Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault

Quick fix

GHSA-fp52-qw33-mfmw — github.com/hashicorp/vault: upgrade to the fixed version with the command below.

go get github.com/hashicorp/vault@v1.2.5

Details

HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured with the AWS IAM auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1..

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/hashicorp/vault
Introduced in: 0.8.1Fixed in: 1.2.5
Fixgo get github.com/hashicorp/vault@v1.2.5
Go/github.com/hashicorp/vault
Introduced in: 1.3.0Fixed in: 1.3.8
Fixgo get github.com/hashicorp/vault@v1.3.8
Go/github.com/hashicorp/vault
Introduced in: 1.4.0Fixed in: 1.4.4
Fixgo get github.com/hashicorp/vault@v1.4.4
Go/github.com/hashicorp/vault
Introduced in: 1.5.0Fixed in: 1.5.1
Fixgo get github.com/hashicorp/vault@v1.5.1

References