Insecure session expiration time In github.com/hashicorp/vault
Description
Token leases could outlive their TTL in HashiCorp Vault HashiCorp Vault and Vault Enterprise 1.0 before 1.5.4 have Incorrect Access Control.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 1.5.4 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4.