PT-2021-19974 · Hashicorp · Vault Enterprise+1

Published

2021-06-03

·

Updated

2024-08-21

·

CVE-2021-32923

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions HashiCorp Vault and Vault Enterprise versions prior to 1.5.9 HashiCorp Vault and Vault Enterprise versions prior to 1.6.5 HashiCorp Vault and Vault Enterprise versions prior to 1.7.2
Description The issue allowed the renewal of nearly-expired token leases and dynamic secret leases, specifically those within 1 second of their maximum TTL, causing them to be incorrectly treated as non-expiring during subsequent use.
Recommendations For versions prior to 1.5.9, update to version 1.5.9 or later. For versions prior to 1.6.5, update to version 1.6.5 or later. For versions prior to 1.7.2, update to version 1.7.2 or later.

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

BIT-VAULT-2021-32923
CVE-2021-32923
GHSA-38J9-7PP9-2HJW
GO-2022-0623

Affected Products

Hashicorp Vault
Vault Enterprise