CVE-2020-10660

Publication date

2020-03-23 12:55:42

Family

mitre

State

PUBLISHED

Description

HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entitys Group membership inadvertently include Groups the Entity no longer has permissions to. Fixed in 1.3.4.