Lack of data validation In github.com/hashicorp/vault-ssh-helper
Description
Improper Input Validation in vault-ssh-helper HashiCorp vault-ssh-helper (github.com/hashicorp/vault-ssh-helper/helper) up to and including version 0.1.6 incorrectly accepted Vault-issued SSH OTPs for the subnet in which a host's network interface was located, rather than the specific IP address assigned to that interface. Fixed in 0.2.0.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 0.2.0 | ||
go | v0.2.0 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.