Improper Resource Shutdown or Release
CVE-2020-7220
Summary
HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails, in certain circumstances, to revoke dynamic secrets for a mount in a deleted namespace. Fixed in 1.3.2.
- MEDIUM
- NETWORK
- NONE
- NONE
- PARTIAL
- NONE
CWE-404 - Improper Resource Shutdown or Release
The program does not release or incorrectly releases a resource before it is made available for re-use.
References
Advisory Timeline
- Published