Security Advisory

CVE-2021-3282

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-02-01 15:38:48
Last updated 2024-08-03 16:53:16
Assigner mitre
State PUBLISHED

Description

HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the `remove-peer` raft operator command to be executed against DR secondaries without authentication. Fixed in 1.6.2.