ZeroHour

CVE-2020-35177

CVSS 3.1
5.3 medium
EPSS
1%p68
Published
()
Modified
Description

HashiCorp Vault and Vault Enterprise 1.4.1 and newer allowed the enumeration of users via the LDAP auth method. Fixed in 1.5.6 and 1.6.1.

Vendors
hashicorp
Products
vault
Weakness
CWE-209
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.