QID 983787

QID 983787: Go (go) Security Update for github.com/hashicorp/vault/ (GHSA-23fq-q7hc-993r)

HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 4.4 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    Customers are advised to refer to GHSA-23fq-q7hc-993r for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 983787

    Software Advisories
    Advisory ID Software Component Link
    GHSA-23fq-q7hc-993r github.com/hashicorp/vault/ URL Logo github.com/advisories/GHSA-23fq-q7hc-993r