QID 982213
QID 982213: Go (go) Security Update for github.com/hashicorp/vault (GHSA-38j9-7pp9-2hjw)
HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-38j9-7pp9-2hjw for updates pertaining to this vulnerability.
Vendor References
- GHSA-38j9-7pp9-2hjw -
github.com/advisories/GHSA-38j9-7pp9-2hjw
CVEs related to QID 982213
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-38j9-7pp9-2hjw | github.com/hashicorp/vault |
|