{"api_version":"1","generated_at":"2026-07-24T17:33:08+00:00","cve":"CVE-2020-10660","urls":{"html":"https://cve.report/CVE-2020-10660","api":"https://cve.report/api/cve/CVE-2020-10660.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-10660","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-10660"},"summary":{"title":"CVE-2020-10660","description":"HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Group membership inadvertently include Groups the Entity no longer has permissions to. Fixed in 1.3.4.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-03-23 13:15:00","updated_at":"2020-03-30 16:04:00"},"problem_types":["CWE-276"],"metrics":[],"references":[{"url":"https://www.hashicorp.com/blog/category/vault/","name":"https://www.hashicorp.com/blog/category/vault/","refsource":"MISC","tags":["Vendor Advisory"],"title":"HashiCorp Blog: Vault","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/hashicorp/vault/blob/master/CHANGELOG.md#134-march-19th-2020","name":"https://github.com/hashicorp/vault/blob/master/CHANGELOG.md#134-march-19th-2020","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"vault/CHANGELOG.md at master · hashicorp/vault · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-10660","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-10660","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"10660","vulnerable":"1","versionEndIncluding":"1.3.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hashicorp","cpe5":"vault","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"-","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"10660","vulnerable":"1","versionEndIncluding":"1.3.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hashicorp","cpe5":"vault","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2020-10660","qid":"997015","title":"GO (Go) Security Update for github.com/hashicorp/vault/vault (GHSA-m979-w9wj-qfj9)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-10660","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Group membership inadvertently include Groups the Entity no longer has permissions to. Fixed in 1.3.4."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://www.hashicorp.com/blog/category/vault/","refsource":"MISC","name":"https://www.hashicorp.com/blog/category/vault/"},{"refsource":"CONFIRM","name":"https://github.com/hashicorp/vault/blob/master/CHANGELOG.md#134-march-19th-2020","url":"https://github.com/hashicorp/vault/blob/master/CHANGELOG.md#134-march-19th-2020"}]}},"nvd":{"publishedDate":"2020-03-23 13:15:00","lastModifiedDate":"2020-03-30 16:04:00","problem_types":["CWE-276"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"0.9.0","versionEndIncluding":"1.3.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*","versionStartIncluding":"0.9.0","versionEndIncluding":"1.3.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"10660","Ordinal":"171100","Title":"CVE-2020-10660","CVE":"CVE-2020-10660","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"10660","Ordinal":"1","NoteData":"HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Group membership inadvertently include Groups the Entity no longer has permissions to. Fixed in 1.3.4.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"10660","Ordinal":"2","NoteData":"2020-03-23","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"10660","Ordinal":"3","NoteData":"2020-03-23","Type":"Other","Title":"Modified"}]}}}