CVE-2020-16251

HIGH8.2EPSS 0.87%

HashiCorp Vault Authentication bypass

發布日:2024/1/31修改日:2024/9/16
也稱為:GHSA-4mp7-2m29-gqxfBIT-vault-2020-16251GO-2024-2488

描述

HashiCorp Vault and Vault Enterprise versions 0.8.3 and newer, when configured with the GCP GCE auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH8.2CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

參考連結(7)