CVE-2020-35453
EUVD-2020-2312717.12.2020, 05:15
HashiCorp Vault Enterprise’s Sentinel EGP policy feature incorrectly allowed requests to be processed in parent and sibling namespaces. Fixed in 1.5.6 and 1.6.1.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hashicorp | vault | 1.5.0 ≤ 𝑥 < 1.5.6 |
| hashicorp | vault | 1.5.0 ≤ 𝑥 < 1.5.6 |
| hashicorp | vault | 1.6.0 ≤ 𝑥 < 1.6.1 |
| hashicorp | vault | 1.6.0 ≤ 𝑥 < 1.6.1 |
𝑥
= Vulnerable software versions
References