MEDIUM6.5
GHSA-hwc3-3qh6-r4gg
HashiCorp Vault's PKI mount vulnerable to denial of service
Quick fix
GHSA-hwc3-3qh6-r4gg — github.com/hashicorp/vault: upgrade to the fixed version with the command below.
go get github.com/hashicorp/vault@v1.11.9Details
HashiCorp Vault's PKI mount issuer endpoints did not correctly authorize access to remove an issuer or modify issuer metadata, potentially resulting in denial of service of the PKI mount. This bug did not affect public or private key material, trust chains or certificate issuance. Fixed in Vault 1.13.1, 1.12.5, and 1.11.9.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/vault
Introduced in:
0Fixed in: 1.11.9Fix
go get github.com/hashicorp/vault@v1.11.9Go/github.com/hashicorp/vault
Introduced in:
1.12.0Fixed in: 1.12.5Fix
go get github.com/hashicorp/vault@v1.12.5Go/github.com/hashicorp/vault
Introduced in:
1.13.0Fixed in: 1.13.1Fix
go get github.com/hashicorp/vault@v1.13.1