VulnerabilityModified
CVE-2020-35453
HashiCorp Vault Enterprise’s Sentinel EGP policy feature incorrectly allowed requests to be processed in parent and sibling namespaces.
MEDIUM 5.3EPSS 0.82%
Does this matter?
Lower severity and a low EPSS score (0.82%). Track it; it rarely justifies an emergency change on its own.
Description
HashiCorp Vault Enterprise’s Sentinel EGP policy feature incorrectly allowed requests to be processed in parent and sibling namespaces. Fixed in 1.5.6 and 1.6.1.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.82% probability · 55th percentile
- CISA KEV
- Not listed
- Affected
- hashicorp/vault
- Source
- cve@mitre.org
References
- https://discuss.hashicorp.com/t/hcsec-2020-24-vault-enterprise-s-sentinel-egp-policies-may-impact-parent-or-sibling-namespaces/18983Vendor Advisory
- https://github.com/hashicorp/vault/blob/master/CHANGELOG.md#161Release Notes
- https://discuss.hashicorp.com/t/hcsec-2020-24-vault-enterprise-s-sentinel-egp-policies-may-impact-parent-or-sibling-namespaces/18983Vendor Advisory
- https://github.com/hashicorp/vault/blob/master/CHANGELOG.md#161Release Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.