—
GO-2024-2509
Improper Authentication in HashiCorp Vault in github.com/hashicorp/vault
Quick fix
GO-2024-2509 — github.com/hashicorp/vault: upgrade to the fixed version with the command below.
go get github.com/hashicorp/vault@v1.6.2Details
Improper Authentication in HashiCorp Vault in github.com/hashicorp/vault
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/vault
Introduced in:
1.6.0Fixed in: 1.6.2Fix
go get github.com/hashicorp/vault@v1.6.2References
- https://github.com/advisories/GHSA-rq95-xf66-j689[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2021-3282[ADVISORY]
- https://github.com/hashicorp/vault/commit/09f9068e22f762da123160233518b440e00bdb3b[FIX]
- https://discuss.hashicorp.com/t/hcsec-2021-04-vault-enterprise-s-dr-secondaries-allowed-raft-peer-removal-without-authentication/20337[WEB]
- https://security.gentoo.org/glsa/202207-01[WEB]