Bug 2167340 (CVE-2020-16251)
Summary: | CVE-2020-16251 vault: GCP Auth Method Allows Authentication Bypass | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Avinash Hanwate <ahanwate> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | amctagga, dfreiber, etamir, jburrell, jcantril, madam, muagarwa, nbecker, nobody, ocs-bugs, periklis, rogbas, tnielsen, vkumar |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | vault 1.2.5, vault 1.3.8, vault 1.4.4, vault 1.5.1 | Doc Type: | --- |
Doc Text: |
A flaw was found in Vault and Vault Enterprise (“Vault”). In affected versions of Vault, with the GCP Auth Method configured and under certain circumstances, the values relied upon by Vault to validate Google Compute Engine (GCE) VMs may be manipulated and bypass authentication.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2023-05-18 08:42:30 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2167349, 2167350, 2167351, 2167354, 2167355, 2167357, 2167359 | ||
Bug Blocks: | 2167338 |
Description
Avinash Hanwate
2023-02-06 10:46:12 UTC
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2023:2138 https://access.redhat.com/errata/RHSA-2023:2138 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-16251 This issue has been addressed in the following products: RHODF-4.13-RHEL-9 Via RHSA-2023:3742 https://access.redhat.com/errata/RHSA-2023:3742 |