CVE-2020-25816
30.09.2020, 20:15
HashiCorp Vault and Vault Enterprise versions 1.0 and newer allowed leases created with a batch token to outlive their TTL because expiration time was not scheduled correctly. Fixed in 1.4.7 and 1.5.4.Enginsight
Vendor | Product | Version |
---|---|---|
hashicorp | vault | 1.0.0 ≤ 𝑥 < 1.4.7 |
hashicorp | vault | 1.0.0 ≤ 𝑥 < 1.4.7 |
hashicorp | vault | 1.5.0 ≤ 𝑥 < 1.5.4 |
hashicorp | vault | 1.5.0 ≤ 𝑥 < 1.5.4 |
𝑥
= Vulnerable software versions