PT-2021-22205 · Hashicorp · Vault Enterprise+1

Published

2021-08-13

·

Updated

2024-08-21

·

CVE-2021-38553

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HashiCorp Vault and Vault Enterprise versions 1.4.0 through 1.7.3
Description The issue is related to the Integrated Storage feature in HashiCorp Vault and Vault Enterprise, where an underlying database file is initialized with excessively broad filesystem permissions. This affects versions 1.4.0 through 1.7.3.
Recommendations For HashiCorp Vault and Vault Enterprise versions 1.4.0 through 1.7.3, update to version 1.8.0 to resolve the issue.

Fix

Improper Preservation of Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-VAULT-2021-38553
CVE-2021-38553
GHSA-23FQ-Q7HC-993R
GO-2022-0620

Affected Products

Hashicorp Vault
Vault Enterprise