Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cr6r-4g38-f69g

Опубликовано: 18 дек. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.

In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.

EPSS

Процентиль: 71%
0.01407
Низкий

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
redhat
больше 4 лет назад

In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.

CVSS3: 4.9
nvd
больше 4 лет назад

In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.

EPSS

Процентиль: 71%
0.01407
Низкий

4.9 Medium

CVSS3