Security Advisory
CVE-2020-10660
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entitys Group membership inadvertently include Groups the Entity no longer has permissions to. Fixed in 1.3.4.