Lack of protection against brute force attacks In github.com/hashicorp/vault
Description
Hashicorp Vault has Lockout Feature Authentication Bypass Vault and Vault Enterprise’s (“Vault”) user lockout feature could be bypassed for Userpass and LDAP authentication methods. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 1.20.1 |
Aliases
1. 2. 3. 4.
References
1.