FS#69015 - [vault] [Security] information disclosure (CVE-2020-35177)
Attached to Project:
Community Packages
Opened by Jonas Witschel (diabonas) - Thursday, 17 December 2020, 14:59 GMT
Last edited by Jonas Witschel (diabonas) - Thursday, 11 February 2021, 13:03 GMT
Opened by Jonas Witschel (diabonas) - Thursday, 17 December 2020, 14:59 GMT
Last edited by Jonas Witschel (diabonas) - Thursday, 11 February 2021, 13:03 GMT
|
Details
Summary
======= The package vault is vulnerable to information disclosure via CVE-2020-35177. Guidance ======== Upgrading to the latest version 1.6.1 or at least to version 1.5.6 from the previous stable series resolves the issue. References ========== https://security.archlinux.org/AVG-1368 https://discuss.hashicorp.com/t/hcsec-2020-25-vault-s-ldap-auth-method-allows-user-enumeration/18984 https://github.com/hashicorp/vault/pull/10537 https://github.com/hashicorp/vault/commit/5f8c7d2502246063d5846841146c68fa60d9bc68 |
This task depends upon
Closed by Jonas Witschel (diabonas)
Thursday, 11 February 2021, 13:03 GMT
Reason for closing: Fixed
Additional comments about closing: vault 1.5.7-1
Thursday, 11 February 2021, 13:03 GMT
Reason for closing: Fixed
Additional comments about closing: vault 1.5.7-1
- https://discuss.hashicorp.com/t/hcsec-2021-02-vault-api-endpoint-exposed-internal-ip-address-without-authentication/20334
- https://discuss.hashicorp.com/t/hcsec-2021-03-vault-api-endpoint-allowed-enumeration-of-secrets-engine-mount-paths-without-authentication/20336