Vulnerabilities
Vulnerable Software
Hashicorp:  >> Vault  >> 1.4.6  Security Vulnerabilities
HashiCorp Vault and Vault Enterprise allowed for enumeration of Secrets Engine mount paths via unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7.
CVSS Score
5.3
EPSS Score
0.005
Published
2021-02-01
HashiCorp Vault and Vault Enterprise versions 1.0 and newer allowed leases created with a batch token to outlive their TTL because expiration time was not scheduled correctly. Fixed in 1.4.7 and 1.5.4.
CVSS Score
6.8
EPSS Score
0.004
Published
2020-09-30


Contact Us

Shodan ® - All rights reserved