Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-7220

Опубликовано: 23 янв. 2020
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails, in certain circumstances, to revoke dynamic secrets for a mount in a deleted namespace. Fixed in 1.3.2.

A flaw was found in HashiCorp Vault Enterprise, where a remote attacker can obtain sensitive information caused by a vulnerability when deleting a namespace. This flaw allows a remote attacker to revoke dynamic secrets for a mount in a deleted namespace.

Отчет

Red Hat Products are not affected by this CVE as this CVE only affects HashiCorp Vault Enterprise versions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-loki-rhel8Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-installerNot affected
Red Hat OpenShift Container Platform 4openshift4/topology-aware-lifecycle-manager-rhel8-operatorNot affected
Red Hat Openshift Container Storage 4ocs4/cephcsi-rhel8Not affected
Red Hat Openshift Container Storage 4ocs4/mcg-rhel8-operatorNot affected
Red Hat Openshift Container Storage 4ocs4/ocs-rhel8-operatorNot affected
Red Hat Openshift Container Storage 4ocs4/rook-ceph-rhel8-operatorNot affected
Red Hat Openshift Data Foundation 4odf4/cephcsi-rhel9Not affected
Red Hat Openshift Data Foundation 4odf4/mcg-rhel9-operatorNot affected
Red Hat Openshift Data Foundation 4odf4/ocs-rhel9-operatorNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2189762vault: Vault Enterprise’s Dynamic Secrets May Persist After Namespace Deletion

EPSS

Процентиль: 53%
0.00305
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 6 лет назад

HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails, in certain circumstances, to revoke dynamic secrets for a mount in a deleted namespace. Fixed in 1.3.2.

CVSS3: 7.5
github
больше 4 лет назад

Improper Resource Shutdown or Release in HashiCorp Vault

EPSS

Процентиль: 53%
0.00305
Низкий

7.5 High

CVSS3