Sensitive information in source code In github.com/hashicorp/vault
Description
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse Vault and Vault Enterprise’s (“Vault”) TOTP Secrets Engine code validation endpoint is susceptible to code reuse within its validity period. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 1.20.1 |
Aliases
1. 2. 3. 4.
References
1.