#VU55909 Security features bypass in Vault and Vault Enterprise - CVE-2021-38553
Published: August 17, 2021 / Updated: August 30, 2021
Vault
Vault Enterprise
HashiCorp
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to an excessively broad filesystem permissions flaw when initialized an underlying database file associated with the Integrated Storage feature. A remote attacker can bypass security features to launch further attacks on the system.