PT-2020-13247 · Google+1 · Gcp Secrets Engine+2
Published
2020-06-10
·
Updated
2024-08-21
·
CVE-2020-12757
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
HashiCorp Vault and Vault Enterprise versions 1.4.0 through 1.4.1
Description
The issue arises when HashiCorp Vault and Vault Enterprise are configured with the GCP Secrets Engine, potentially leading to the incorrect generation of GCP Credentials with a default time-to-live lease duration instead of the engine-configured setting. This may result in generated GCP credentials being valid for longer than intended. The problem is related to improper input validation and incorrect access control in the Go package github.com/hashicorp/vault-plugin-secrets-gcp/plugin.
Recommendations
For HashiCorp Vault and Vault Enterprise versions 1.4.0 and 1.4.1, update to version 1.4.2 to resolve the issue.
Fix
Improper Privilege Management
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gcp Secrets Engine
Hashicorp Vault
Vault Enterprise