LOW3.7
GHSA-mwgr-84fv-3jh9
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users
Quick fix
GHSA-mwgr-84fv-3jh9 — github.com/hashicorp/vault: upgrade to the fixed version with the command below.
go get github.com/hashicorp/vault@v1.20.1Details
A timing side channel in Vault and Vault Enterprise’s (“Vault”) userpass auth method allowed an attacker to distinguish between existing and non-existing users, and potentially enumerate valid usernames for Vault’s Userpass auth method. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/vault
Introduced in:
0Fixed in: 1.20.1Fix
go get github.com/hashicorp/vault@v1.20.1