| Type | URI |
|---|---|
| Vendor Advisory | https://discuss.hashicorp.com/t/hcsec-2021-02-vault-api-endpoint-exposed-internal-ip-address-without-authentication/20334 |
| CPE URI | Source package | Min version | Max version |
|---|---|---|---|
cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:* |
vault | >= None | < 1.5.7 |
cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:* |
vault | >= 1.6.0 | < 1.6.2 |
| Source package | Branch | Version | Maintainer | Status |
|---|---|---|---|---|
| vault | edge-community | 1.5.7-r0 | None | fixed |
| vault | edge-community | 1.5.6-r0 | None | possibly vulnerable |
| vault | edge-community | 1.5.4-r0 | None | possibly vulnerable |
| vault | edge-community | 1.4.3-r0 | None | possibly vulnerable |
| vault | 3.18-community | 1.5.7-r0 | None | fixed |
| vault | 3.17-community | 1.5.7-r0 | None | fixed |