PT-2020-14842 · Hashicorp · Vault Enterprise+1

Published

2020-08-26

·

Updated

2025-06-21

·

CVE-2020-16250

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer
Description The issue concerns an authentication bypass when HashiCorp Vault and Vault Enterprise are configured with the AWS IAM auth method. This could potentially allow unauthorized access. The estimated number of affected devices is not specified.
Recommendations For versions 0.7.1 and newer, update to version 1.2.5, 1.3.8, 1.4.4, or 1.5.1 to resolve the issue. As a temporary workaround, consider restricting the use of the AWS IAM auth method until a patch is applied.

Fix

Authentication Bypass by Spoofing

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

BIT-VAULT-2020-16250
CVE-2020-16250
GHSA-FP52-QW33-MFMW
GO-2022-0825

Affected Products

Hashicorp Vault
Vault Enterprise