CRITICAL9.1
GHSA-mr4h-qf9j-f665
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration
Quick fix
GHSA-mr4h-qf9j-f665 — github.com/hashicorp/vault: upgrade to the fixed version with the command below.
go get github.com/hashicorp/vault@v1.20.1Details
A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plugin directory is set in Vault’s configuration. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/vault
Introduced in:
0.8.0Fixed in: 1.20.1Fix
go get github.com/hashicorp/vault@v1.20.1