CVE-2021-32923

HIGH7.4EPSS 0.21%

Invalid session token expiration

發布日:2021/6/8修改日:2026/2/4
也稱為:GHSA-38j9-7pp9-2hjwBIT-vault-2021-32923CGA-v8p9-4843-p8j6GO-2022-0623

描述

HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

參考連結(6)