Vulnerabilities
Vulnerable Software
Hashicorp:  >> Vault  >> 1.5.8  Security Vulnerabilities
HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.
CVSS Score
7.4
EPSS Score
0.007
Published
2021-06-03
HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not validate TLS certificates when connecting to Cassandra clusters. Fixed in 1.6.4 and 1.7.1
CVSS Score
7.5
EPSS Score
0.002
Published
2021-04-22


Contact Us

Shodan ® - All rights reserved