/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2020-16250

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2020-16250

CGA ID

CGA-h425-mx3f-g92v

Severity

8.2

High

CVSS V3

Description

HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured with the AWS IAM auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1..

References

  • https://images.chainguard.dev/security/CGA-h425-mx3f-g92v

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images