CVE-2020-10660 (Medium) detected in github.com/hashicorp/vault-v1.3.1 #2530
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
stale
All issues that are marked as stale due to inactivity
CVE-2020-10660 - Medium Severity Vulnerability
A tool for secrets management, encryption as a service, and privileged access management
Dependency Hierarchy:
Found in HEAD commit: 4213ed86dc859b83c4f126853835fab3dc987b5d
Found in base branch: main
HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Group membership inadvertently include Groups the Entity no longer has permissions to. Fixed in 1.3.4.
Publish Date: 2020-03-23
URL: CVE-2020-10660
Base Score Metrics:
Type: Upgrade version
Origin: https://github.com/hashicorp/vault/blob/master/CHANGELOG.md#134-march-19th-2020
Release Date: 2020-03-23
Fix Resolution: 1.3.4
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: