Описание
HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0.
Ссылки
- Vendor Advisory
- Third Party Advisory
- Vendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 1.4.0 (включая) до 1.8.0 (исключая)Версия от 1.4.0 (включая) до 1.8.0 (исключая)
Одно из
cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*
EPSS
Процентиль: 26%
0.00086
Низкий
4.4 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-281
Связанные уязвимости
CVSS3: 4.4
redhat
почти 4 года назад
HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0.
CVSS3: 9.8
github
почти 4 года назад
HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0
EPSS
Процентиль: 26%
0.00086
Низкий
4.4 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-281