MEDIUM5.7
GHSA-v6r4-35f9-9rpw
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability
Quick fix
GHSA-v6r4-35f9-9rpw — github.com/hashicorp/vault: upgrade to the fixed version with the command below.
go get github.com/hashicorp/vault@v1.20.1Details
Vault and Vault Enterprise’s (“Vault”) login MFA rate limits could be bypassed and TOTP tokens could be reused. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/vault
Introduced in:
1.10.0Fixed in: 1.20.1Fix
go get github.com/hashicorp/vault@v1.20.1