Lack of protection against brute force attacks In github.com/hashicorp/vault
Description
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability Vault and Vault Enterprise’s (“Vault”) login MFA rate limits could be bypassed and TOTP tokens could be reused. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 1.20.1 |
Aliases
1. 2. 3. 4.
References
1.