HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0.
References
Link | Resource |
---|---|
https://discuss.hashicorp.com/t/hcsec-2021-20-vault-s-integrated-storage-backend-database-file-may-have-excessively-broad-permissions/28168 | Vendor Advisory |
https://security.gentoo.org/glsa/202207-01 | Third Party Advisory |
https://discuss.hashicorp.com/t/hcsec-2021-20-vault-s-integrated-storage-backend-database-file-may-have-excessively-broad-permissions/28168 | Vendor Advisory |
https://security.gentoo.org/glsa/202207-01 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 06:17
Type | Values Removed | Values Added |
---|---|---|
References | () https://discuss.hashicorp.com/t/hcsec-2021-20-vault-s-integrated-storage-backend-database-file-may-have-excessively-broad-permissions/28168 - Vendor Advisory | |
References | () https://security.gentoo.org/glsa/202207-01 - Third Party Advisory |
Information
Published : 2021-08-13 16:15
Updated : 2024-11-21 06:17
NVD link : CVE-2021-38553
Mitre link : CVE-2021-38553
CVE.ORG link : CVE-2021-38553
JSON object : View
Products Affected
hashicorp
- vault
CWE
CWE-281
Improper Preservation of Permissions