CVE-2020-35177
17.12.2020, 05:15
HashiCorp Vault and Vault Enterprise 1.4.1 and newer allowed the enumeration of users via the LDAP auth method. Fixed in 1.5.6 and 1.6.1.Enginsight
Vendor | Product | Version |
---|---|---|
hashicorp | vault | 1.5.0 ≤ 𝑥 < 1.5.6 |
hashicorp | vault | 1.5.0 ≤ 𝑥 < 1.5.6 |
hashicorp | vault | 1.6.0 ≤ 𝑥 < 1.6.1 |
hashicorp | vault | 1.6.0 ≤ 𝑥 < 1.6.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration