HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0.
References
Link | Resource |
---|---|
https://discuss.hashicorp.com/t/hcsec-2021-20-vault-s-integrated-storage-backend-database-file-may-have-excessively-broad-permissions/28168 | Vendor Advisory |
https://security.gentoo.org/glsa/202207-01 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-08-13 09:15
Updated : 2022-10-25 13:54
NVD link : CVE-2021-38553
Mitre link : CVE-2021-38553
JSON object : View
CWE
CWE-281
Improper Preservation of Permissions
Products Affected
hashicorp
- vault