Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cr6r-4g38-f69g

Опубликовано: 18 дек. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.

In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.

EPSS

Процентиль: 62%
0.00435
Низкий

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
redhat
около 4 лет назад

In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.

CVSS3: 4.9
nvd
около 4 лет назад

In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.

EPSS

Процентиль: 62%
0.00435
Низкий

4.9 Medium

CVSS3