CVE-2021-32923

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/06/2021
Last modified:
25/10/2022

Description

HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:* 0.10.0 (including) 1.5.9 (excluding)
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* 0.10.0 (including) 1.5.9 (excluding)
cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:* 1.6.0 (including) 1.6.5 (excluding)
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* 1.6.0 (including) 1.6.5 (excluding)
cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:* 1.7.0 (including) 1.7.2 (excluding)
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* 1.7.0 (including) 1.7.2 (excluding)