PT-2021-22206 · Hashicorp · Vault Enterprise+1

Avinash Kumar

·

Published

2021-08-13

·

Updated

2024-08-21

·

CVE-2021-38554

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HashiCorp Vault and Vault Enterprise versions prior to 1.8.0 HashiCorp Vault and Vault Enterprise versions 1.7.x prior to 1.7.4 HashiCorp Vault and Vault Enterprise versions 1.6.x prior to 1.6.6
Description The UI of HashiCorp Vault and Vault Enterprise erroneously cached and exposed user-viewed secrets between sessions in a single shared browser.
Recommendations For versions prior to 1.8.0, update to version 1.8.0 or later. For versions 1.7.x, update to version 1.7.4 or later. For versions 1.6.x, update to version 1.6.6 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-VAULT-2021-38554
CVE-2021-38554
GHSA-6239-28C2-9MRM
GO-2022-0632

Affected Products

Hashicorp Vault
Vault Enterprise