CVE-2021-27400 (High) detected in github.com/hashicorp/vault-v1.3.1 #2552
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
stale
All issues that are marked as stale due to inactivity
CVE-2021-27400 - High Severity Vulnerability
A tool for secrets management, encryption as a service, and privileged access management
Dependency Hierarchy:
Found in HEAD commit: 4213ed86dc859b83c4f126853835fab3dc987b5d
Found in base branch: main
HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not validate TLS certificates when connecting to Cassandra clusters. Fixed in 1.6.4 and 1.7.1
Publish Date: 2021-04-22
URL: CVE-2021-27400
Base Score Metrics:
Type: Upgrade version
Origin: https://discuss.hashicorp.com/t/hcsec-2021-10-vault-s-cassandra-integrations-did-not-validate-tls-certificates/23463
Release Date: 2021-04-22
Fix Resolution: v1.6.4,v1.7.1
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: