Improper Authentication in HashiCorp Vault
High severity
GitHub Reviewed
Published
Jan 31, 2024
to the GitHub Advisory Database
Package
Affected versions
>= 1.6.0, < 1.6.2
Patched versions
1.6.2
Description
Published by the National Vulnerability Database
Feb 1, 2021
Published to the GitHub Advisory Database
Jan 31, 2024
Reviewed
Jan 31, 2024
HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the
remove-peer
raft operator command to be executed against DR secondaries without authentication. Fixed in 1.6.2.References