—
GO-2022-0611
HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault
Quick fix
GO-2022-0611 — github.com/hashicorp/vault: upgrade to the fixed version with the command below.
go get github.com/hashicorp/vault@v1.7.6Details
HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/vault
Introduced in:
0.11.0Fixed in: 1.7.6Fix
go get github.com/hashicorp/vault@v1.7.6References
- https://github.com/advisories/GHSA-pfmw-vj74-ph8g[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2021-43998[ADVISORY]
- https://discuss.hashicorp.com/t/hcsec-2021-30-vaults-templated-acl-policies-matched-first-created-alias-per-entity-and-auth-backend/32132[WEB]
- https://security.gentoo.org/glsa/202207-01[WEB]