CVE-2020-35453
17.12.2020, 05:15
HashiCorp Vault Enterprises Sentinel EGP policy feature incorrectly allowed requests to be processed in parent and sibling namespaces. Fixed in 1.5.6 and 1.6.1.Enginsight
Vendor | Product | Version |
---|---|---|
hashicorp | vault | 1.5.0 ≤ 𝑥 < 1.5.6 |
hashicorp | vault | 1.5.0 ≤ 𝑥 < 1.5.6 |
hashicorp | vault | 1.6.0 ≤ 𝑥 < 1.6.1 |
hashicorp | vault | 1.6.0 ≤ 𝑥 < 1.6.1 |
𝑥
= Vulnerable software versions
References