PT-2020-14842 · Hashicorp · Vault Enterprise+1
Published
2020-08-26
·
Updated
2025-06-21
·
CVE-2020-16250
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer
Description
The issue concerns an authentication bypass when HashiCorp Vault and Vault Enterprise are configured with the AWS IAM auth method. This could potentially allow unauthorized access. The estimated number of affected devices is not specified.
Recommendations
For versions 0.7.1 and newer, update to version 1.2.5, 1.3.8, 1.4.4, or 1.5.1 to resolve the issue.
As a temporary workaround, consider restricting the use of the AWS IAM auth method until a patch is applied.
Fix
Authentication Bypass by Spoofing
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hashicorp Vault
Vault Enterprise