CVE-2021-38554

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/08/2021
Last modified:
08/09/2022

Description

HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser. Fixed in 1.8.0 and pending 1.7.4 / 1.6.6 releases.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:* 1.8.0 (excluding)
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:* 1.8.0 (excluding)