Input validation error in Vault - CVE-2020-25816
Published: September 30, 2020 / Updated: October 26, 2020
Vulnerability identifier: #VU47911
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-25816
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
HashiCorp Vault and Vault Enterprise versions 1.0 and newer allowed leases created with a batch token to outlive their TTL because expiration time was not scheduled correctly. Fixed in 1.4.7 and 1.5.4.
Affected software
Vault
vault (Alpine package)
vault (Alpine package)
How to mitigate CVE-2020-25816
Install update from vendor's website.
Vault - update to 1.5.4
vault (Alpine package) - update to 1.5.4-r0
vault (Alpine package) - update to 1.5.4-r0