CVE-2021-38553
EUVD-2021-150313.08.2021, 16:15
HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hashicorp | vault | 1.4.0 ≤ 𝑥 < 1.8.0 |
| hashicorp | vault | 1.4.0 ≤ 𝑥 < 1.8.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References