-
Notifications
You must be signed in to change notification settings - Fork 74
Closed
Labels
excluded: NOT_IMPORTABLEThis vulnerability only exists in a binary and is not importable.This vulnerability only exists in a binary and is not importable.
Description
In GitHub Security Advisory GHSA-23fq-q7hc-993r, there is a vulnerability in the following Go packages or modules:
| Unit | Fixed | Vulnerable Ranges |
|---|---|---|
| github.com/hashicorp/vault | 1.8.0 | >= 1.4.0, < 1.8.0 |
See doc/triage.md for instructions on how to triage this report.
packages:
- package: github.com/hashicorp/vault
versions:
- introduced: 1.4.0
fixed: 1.8.0
description: HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized
an underlying database file associated with the Integrated Storage feature with
excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise
1.8.0.
published: 2021-08-30T17:22:53Z
last_modified: 2022-07-18T20:08:59Z
cves:
- CVE-2021-38553
ghsas:
- GHSA-23fq-q7hc-993r
links:
context:
- https://github.com/advisories/GHSA-23fq-q7hc-993r
Metadata
Metadata
Assignees
Labels
excluded: NOT_IMPORTABLEThis vulnerability only exists in a binary and is not importable.This vulnerability only exists in a binary and is not importable.