HIGH8.2
GHSA-fp52-qw33-mfmw
Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault
Quick fix
GHSA-fp52-qw33-mfmw — github.com/hashicorp/vault: upgrade to the fixed version with the command below.
go get github.com/hashicorp/vault@v1.2.5Details
HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured with the AWS IAM auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1..
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/vault
Introduced in:
0.8.1Fixed in: 1.2.5Fix
go get github.com/hashicorp/vault@v1.2.5Go/github.com/hashicorp/vault
Introduced in:
1.3.0Fixed in: 1.3.8Fix
go get github.com/hashicorp/vault@v1.3.8Go/github.com/hashicorp/vault
Introduced in:
1.4.0Fixed in: 1.4.4Fix
go get github.com/hashicorp/vault@v1.4.4Go/github.com/hashicorp/vault
Introduced in:
1.5.0Fixed in: 1.5.1Fix
go get github.com/hashicorp/vault@v1.5.1References
- https://nvd.nist.gov/vuln/detail/CVE-2020-16250[ADVISORY]
- https://github.com/hashicorp/vault[PACKAGE]
- https://github.com/hashicorp/vault/blob/master/CHANGELOG.md#151[WEB]
- https://www.hashicorp.com/blog/category/vault[WEB]
- http://packetstormsecurity.com/files/159478/Hashicorp-Vault-AWS-IAM-Integration-Authentication-Bypass.html[WEB]