Please read this before reporting a bug:
http://wiki.archlinux.org/index.php/Reporting_Bug_Guidelines
Do NOT report bugs when a package is just outdated, or it is in Unsupported. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
http://wiki.archlinux.org/index.php/Reporting_Bug_Guidelines
Do NOT report bugs when a package is just outdated, or it is in Unsupported. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
FS#69015 - [vault] [Security] information disclosure (CVE-2020-35177)
Attached to Project:
Community Packages
Opened by Jonas Witschel (diabonas) - Thursday, 17 December 2020, 14:59 GMT
Opened by Jonas Witschel (diabonas) - Thursday, 17 December 2020, 14:59 GMT
|
DetailsSummary
======= The package vault is vulnerable to information disclosure via CVE-2020-35177. Guidance ======== Upgrading to the latest version 1.6.1 or at least to version 1.5.6 from the previous stable series resolves the issue. References ========== https://security.archlinux.org/AVG-1368 https://discuss.hashicorp.com/t/hcsec-2020-25-vault-s-ldap-auth-method-allows-user-enumeration/18984 https://github.com/hashicorp/vault/pull/10537 https://github.com/hashicorp/vault/commit/5f8c7d2502246063d5846841146c68fa60d9bc68 |
This task depends upon