CVE-2020-35177

HashiCorp Vault and Vault Enterprise 1.4.1 and newer allowed the enumeration of users via the LDAP auth method. Fixed in 1.5.6 and 1.6.1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*

History

08 Jan 2021, 18:15

Type Values Removed Values Added
Summary HashiCorp Vault and Vault Enterprise allowed the enumeration of users via the LDAP auth method. Fixed in 1.5.6 and 1.6.1. HashiCorp Vault and Vault Enterprise 1.4.1 and newer allowed the enumeration of users via the LDAP auth method. Fixed in 1.5.6 and 1.6.1.

Information

Published : 2020-12-17 05:15

Updated : 2023-12-10 13:41


NVD link : CVE-2020-35177

Mitre link : CVE-2020-35177

CVE.ORG link : CVE-2020-35177


JSON object : View

Products Affected

hashicorp

  • vault
CWE
CWE-209

Generation of Error Message Containing Sensitive Information