ZeroHour

CVE-2020-35453

CVSS 3.1
5.3 medium
EPSS
<1%p55
Published
()
Modified
Description

HashiCorp Vault Enterprise’s Sentinel EGP policy feature incorrectly allowed requests to be processed in parent and sibling namespaces. Fixed in 1.5.6 and 1.6.1.

Vendors
hashicorp
Products
vault
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.