CVE-2020-16251

Description

HashiCorp Vault and Vault Enterprise versions 0.8.3 and newer, when configured with the GCP GCE auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1.

Risk Information

Base Score
8.2
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
EPSS Score
Exploitation Probability
0.923

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2020-16250,CVE-2020-16251 are affected in HashiCorp Vault Enterprise 1.2.4Windows
Vulnerabilities CVE-2020-16250,CVE-2020-16251 are affected in HashiCorp Vault Enterprise 1.3.7Windows
Vulnerabilities CVE-2020-16250,CVE-2020-16251 are affected in HashiCorp Vault Enterprise 1.4.3Windows
Vulnerabilities CVE-2020-16250,CVE-2020-16251 are affected in HashiCorp Vault Enterprise 1.5.0Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234