Information disclosure in Vault - CVE-2020-35177

 

Information disclosure in Vault - CVE-2020-35177

Published: December 23, 2020 / Updated: February 26, 2021


Vulnerability identifier: #VU49141
CSH Severity: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-35177
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Vault
Software vendor:
HashiCorp

Description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

HashiCorp Vault and Vault Enterprise allowed the enumeration of users via the LDAP auth method.


Remediation

Install update from vendor's website.

External links