VDB
Sign up
CRITICAL9.1

GHSA-mr4h-qf9j-f665

Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration

Quick fix

GHSA-mr4h-qf9j-f665 — github.com/hashicorp/vault: upgrade to the fixed version with the command below.

go get github.com/hashicorp/vault@v1.20.1

Details

A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plugin directory is set in Vault’s configuration. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/hashicorp/vault
Introduced in: 0.8.0Fixed in: 1.20.1
Fixgo get github.com/hashicorp/vault@v1.20.1

References