Описание
HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.
Ссылки
- Vendor Advisory
- Third Party Advisory
- ProductVendor Advisory
- Vendor Advisory
- Third Party Advisory
- ProductVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 0.10.0 (включая) до 1.5.9 (исключая)Версия от 0.10.0 (включая) до 1.5.9 (исключая)Версия от 1.6.0 (включая) до 1.6.5 (исключая)Версия от 1.6.0 (включая) до 1.6.5 (исключая)Версия от 1.7.0 (включая) до 1.7.2 (исключая)Версия от 1.7.0 (включая) до 1.7.2 (исключая)
Одно из
cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*
EPSS
Процентиль: 70%
0.00654
Низкий
7.4 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-613
Связанные уязвимости
CVSS3: 6.5
redhat
больше 4 лет назад
HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.
EPSS
Процентиль: 70%
0.00654
Низкий
7.4 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-613