Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-38j9-7pp9-2hjw

Опубликовано: 08 июн. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.4

Описание

Invalid session token expiration

HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.

Пакеты

Наименование

github.com/hashicorp/vault

go
Затронутые версииВерсия исправления

>= 1.7.0, < 1.7.2

1.7.2

Наименование

github.com/hashicorp/vault

go
Затронутые версииВерсия исправления

>= 1.6.0, < 1.6.5

1.6.5

Наименование

github.com/hashicorp/vault

go
Затронутые версииВерсия исправления

>= 0.10.0, < 1.5.9

1.5.9

EPSS

Процентиль: 70%
0.00654
Низкий

7.4 High

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 6.5
redhat
больше 4 лет назад

HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.

CVSS3: 7.4
nvd
больше 4 лет назад

HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.

CVSS3: 7.4
msrc
больше 1 года назад

Описание отсутствует

EPSS

Процентиль: 70%
0.00654
Низкий

7.4 High

CVSS3

Дефекты

CWE-613