Input validation error in Vault Enterprise and Vault - CVE-2021-3024

 

Input validation error in Vault Enterprise and Vault - CVE-2021-3024

Published: February 1, 2021 / Updated: February 26, 2021


Vulnerability identifier: #VU50454
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3024
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

HashiCorp Vault and Vault Enterprise disclosed the internal IP address of the Vault node when responding to some invalid, unauthenticated HTTP requests.


Affected software

Vault Enterprise
Vault
Gentoo Linux
vault (Alpine package)

How to mitigate CVE-2021-3024

Install update from vendor's website.

Vault Enterprise - addressed in versions 1.5.7, 1.6.2
Vault - addressed in versions 1.5.7, 1.6.2
vault (Alpine package) - update to 1.5.7-r0

External References

Related Security Bulletins