Improper Authentication in HashiCorp Vault
High severity
GitHub Reviewed
Published
Jan 31, 2024
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Feb 1, 2021
Published to the GitHub Advisory Database
Jan 31, 2024
Reviewed
Jan 31, 2024
HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the
remove-peer
raft operator command to be executed against DR secondaries without authentication. Fixed in 1.6.2.References