HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Group membership inadvertently include Groups the Entity no longer has permissions to. Fixed in 1.3.4.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2024-0384 | HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Group membership inadvertently include Groups the Entity no longer has permissions to. Fixed in 1.3.4. |
![]() |
GHSA-m979-w9wj-qfj9 | HashiCorp Vault Improper Privilege Management |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T11:06:10.655Z
Reserved: 2020-03-18T00:00:00
Link: CVE-2020-10660

No data.

Status : Modified
Published: 2020-03-23T13:15:13.127
Modified: 2024-11-21T04:55:47.377
Link: CVE-2020-10660


No data.