PT-2020-13247 · Google+1 · Gcp Secrets Engine+2

Published

2020-06-10

·

Updated

2024-08-21

·

CVE-2020-12757

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HashiCorp Vault and Vault Enterprise versions 1.4.0 through 1.4.1
Description The issue arises when HashiCorp Vault and Vault Enterprise are configured with the GCP Secrets Engine, potentially leading to the incorrect generation of GCP Credentials with a default time-to-live lease duration instead of the engine-configured setting. This may result in generated GCP credentials being valid for longer than intended. The problem is related to improper input validation and incorrect access control in the Go package github.com/hashicorp/vault-plugin-secrets-gcp/plugin.
Recommendations For HashiCorp Vault and Vault Enterprise versions 1.4.0 and 1.4.1, update to version 1.4.2 to resolve the issue.

Fix

Improper Privilege Management

RCE

Weakness Enumeration

Related Identifiers

BIT-VAULT-2020-12757
CVE-2020-12757
GHSA-75PC-QVWC-JF3G
GO-2022-0804

Affected Products

Gcp Secrets Engine
Hashicorp Vault
Vault Enterprise