Back to bug 2189536

Who When What Removed Added
Red Hat Bugzilla 2023-05-31 23:37:40 UTC CC mrajanna
Red Hat Bugzilla 2023-07-07 08:30:23 UTC Assignee security-response-team nobody
Avinash Hanwate 2023-07-11 06:24:10 UTC Doc Text HashiCorp Vault and Vault Enterprise could allow a remote attacker to obtain sensitive information. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to perform enumeration of Secrets Engine mount paths.
RaTasha Tillery-Smith 2023-07-11 13:45:26 UTC Doc Text HashiCorp Vault and Vault Enterprise could allow a remote attacker to obtain sensitive information. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to perform enumeration of Secrets Engine mount paths. A flaw was found in HashiCorp Vault and Vault Enterprise. This flaw allows a remote attacker to obtain sensitive information. By sending a specially-crafted request, a remote attacker can perform enumeration of the Secrets Engine mount paths.
Avinash Hanwate 2023-07-18 13:23:08 UTC Blocks 2223663
Avinash Hanwate 2023-07-18 13:42:17 UTC CC jcantril, periklis
Fixed In Version Vault 1.6.2, valut 1.5.7
Avinash Hanwate 2023-07-18 13:42:33 UTC Depends On 2223674
Red Hat Bugzilla 2023-08-03 08:30:13 UTC CC ocs-bugs

Back to bug 2189536