CVE-2020-7220

HIGH7.5EPSS 0.29%

Improper Resource Shutdown or Release in HashiCorp Vault

Published: 7/28/2021Modified: 8/21/2024
Also known as:GHSA-9vh5-r4qw-v3vvBIT-vault-2020-7220GO-2022-0816

Description

HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails, in certain circumstances, to revoke dynamic secrets for a mount in a deleted namespace. Fixed in 1.3.2.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References (5)