VDB
CVE-2021-32923
CVE-2021-32923
PUBLISHED
HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.
EPSS 0.21% · 43.9th percentile
Risk Scores
EPSS Score
0.21%
43.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | vault | 0.10.0, 1.7.0, 1.6.0 |
| Bitnami | vault | 1.6.0, 1.7.0, 0.10.0 |
Timeline
- Jun 3, 2021 CVE Published
- Jun 4, 2021 EPSS Score
- Jun 19, 2021 EPSS Score
- Aug 6, 2021 EPSS Score
- Oct 6, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 5, 2022 EPSS Score
- Apr 6, 2022 EPSS Score
- Jun 6, 2022 EPSS Score
- Oct 7, 2022 EPSS Score
- Dec 7, 2022 EPSS Score