Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-32923

Опубликовано: 03 июн. 2021
Источник: redhat
CVSS3: 6.5

Описание

HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.

A flaw was found in the HashiCorp Vault and Vault Enterprise. The vault could allow a remote attacker to bypass security restrictions caused by a renewal logic flaw when a token lease or dynamic secret lease was renewed inside the last second of its maximum TTL. By sending a specially crafted request, an attacker can bypass authentication validation and gain access to the system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-loki-rhel8Not affected
OpenShift Service Mesh 2.0servicemeshNot affected
Red Hat Advanced Cluster Management for Kubernetes 2vaultNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-installerNot affected
Red Hat OpenShift Container Platform 4openshift4/topology-aware-lifecycle-manager-rhel8-operatorNot affected
Red Hat Openshift Container Storage 4ocs4/cephcsi-rhel8Under investigation
Red Hat Openshift Container Storage 4ocs4/mcg-rhel8-operatorUnder investigation
Red Hat Openshift Container Storage 4ocs4/ocs-rhel8-operatorUnder investigation
Red Hat Openshift Container Storage 4ocs4/rook-ceph-rhel8-operatorUnder investigation
Red Hat Openshift Data Foundation 4odf4/cephcsi-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-613
https://bugzilla.redhat.com/show_bug.cgi?id=1968032vault: Token leases incorrectly treated as non-expiring

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.4
nvd
больше 4 лет назад

HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.

CVSS3: 7.4
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 7.4
github
больше 4 лет назад

Invalid session token expiration

6.5 Medium

CVSS3