ZeroHour

CVE-2021-27668

CVSS 3.1
5.3 medium
EPSS
1%p62
Published
()
Modified
Description

HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metadata from DR secondaries without authentication. Fixed in 1.6.3.

Vendors
hashicorp
Products
vault
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.