QID 982213

QID 982213: Go (go) Security Update for github.com/hashicorp/vault (GHSA-38j9-7pp9-2hjw)

HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.4 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Customers are advised to refer to GHSA-38j9-7pp9-2hjw for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982213

    Software Advisories
    Advisory ID Software Component Link
    GHSA-38j9-7pp9-2hjw github.com/hashicorp/vault URL Logo github.com/advisories/GHSA-38j9-7pp9-2hjw