HashiCorp Vault and Vault Enterprise allowed for enumeration of Secrets Engine mount paths via unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vault | Hashicorp | * | 1.5.7 (excluding) |
Vault | Hashicorp | 1.6.0 (including) | 1.6.2 (excluding) |