PT-2020-17282 · Hashicorp · Vault

Koharin

·

Published

2020-12-17

·

Updated

2024-03-06

·

CVE-2020-35192

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Vault versions prior to 0.11.6
Description The issue concerns Vault Docker images that have a blank password set for the root user. This could allow a remote attacker to gain root access to systems using the affected Vault Docker container.
Recommendations For versions prior to 0.11.6, update to version 0.11.6 or later to resolve the issue. As a temporary workaround, consider changing the root password in the Vault Docker container to prevent unauthorized access.

Exploit

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

BIT-VAULT-2020-35192
CVE-2020-35192

Affected Products

Vault