HIGH7.2
GHSA-6h4p-m86h-hhgh
Hashicorp Vault has Privilege Escalation Vulnerability
Quick fix
GHSA-6h4p-m86h-hhgh — github.com/hashicorp/vault: upgrade to the fixed version with the command below.
go get github.com/hashicorp/vault@v1.20.0Details
A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s token privileges to Vault’s root policy. Fixed in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11 and 1.16.22.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/vault
Introduced in:
0.10.4Fixed in: 1.20.0Fix
go get github.com/hashicorp/vault@v1.20.0