ZeroHour

CVE-2021-38553

CVSS 3.1
4.4 medium
EPSS
<1%p19
Published
()
Modified
Description

HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0.

Vendors
hashicorp
Products
vault
Weakness
CWE-281
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.