CVE Vulnerabilities

CVE-2020-25816

Published: Sep 30, 2020 | Modified: Sep 07, 2021
CVSS 3.x
6.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
4.9 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

HashiCorp Vault and Vault Enterprise versions 1.0 and newer allowed leases created with a batch token to outlive their TTL because expiration time was not scheduled correctly. Fixed in 1.4.7 and 1.5.4.

Affected Software

Name Vendor Start Version End Version
Vault Hashicorp 1.0.0 (including) 1.4.7 (excluding)
Vault Hashicorp 1.5.0 (including) 1.5.4 (excluding)

References