Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-38554

Опубликовано: 13 авг. 2021
Источник: redhat
CVSS3: 5.3

Описание

HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser. Fixed in 1.8.0 and pending 1.7.4 / 1.6.6 releases.

A flaw was found in the vault package. The Vault UI web application may fail to completely clear a client-side data cache on user logout. As a result, an authenticated user sharing a browser to access Vault may have been able to view the previous authenticated user’s cached secrets, even if they were not authorized by Vault policies to view them.

Отчет

The Vault deployments that do not enable the Vault UI are not affected by this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-loki-rhel8Not affected
OpenShift Service Mesh 2.0servicemeshNot affected
Red Hat Advanced Cluster Management for Kubernetes 2vaultNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-installerWill not fix
Red Hat OpenShift Container Platform 4openshift4/topology-aware-lifecycle-manager-rhel8-operatorWill not fix
Red Hat Openshift Container Storage 4ocs4/cephcsi-rhel8Out of support scope
Red Hat Openshift Container Storage 4ocs4/mcg-rhel8-operatorOut of support scope
Red Hat Openshift Container Storage 4ocs4/ocs-rhel8-operatorOut of support scope
Red Hat Openshift Container Storage 4ocs4/rook-ceph-rhel8-operatorOut of support scope
Red Hat Openshift Data Foundation 4odf4/cephcsi-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1995207vault: UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
больше 4 лет назад

HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser. Fixed in 1.8.0 and pending 1.7.4 / 1.6.6 releases.

CVSS3: 5.3
github
больше 4 лет назад

Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault

5.3 Medium

CVSS3