PT-2020-19474 · Hashicorp · Hashicorp Vault Enterprise

CVE-2020-7220

·

Published

2020-01-23

·

Updated

2024-08-21

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HashiCorp Vault Enterprise versions 0.11.0 through 1.3.1
Description The issue arises when HashiCorp Vault Enterprise fails to revoke dynamic secrets for a mount in a deleted namespace under certain circumstances. This problem does not specify the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
Recommendations For versions 0.11.0 through 1.3.1, update to version 1.3.2 to resolve the issue.

Fix

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-VAULT-2020-7220
CVE-2020-7220
GHSA-9VH5-R4QW-V3VV
GO-2022-0816

Affected Products

Hashicorp Vault Enterprise