Bug 2167400 (CVE-2020-12757) - CVE-2020-12757 vault: GCP Credentials are created with incorrect time-to-live lease duration
Summary: CVE-2020-12757 vault: GCP Credentials are created with incorrect time-to-live...
Keywords:
Status: NEW
Alias: CVE-2020-12757
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2167760
Blocks: 2167459
TreeView+ depends on / blocked
 
Reported: 2023-02-06 14:26 UTC by Pedro Sampaio
Modified: 2025-03-17 23:44 UTC (History)
13 users (show)

Fixed In Version: vault 1.4.2
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Pedro Sampaio 2023-02-06 14:26:37 UTC
HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly generate GCP Credentials with the default time-to-live lease duration instead of the engine-configured setting. This may lead to generated GCP credentials being valid for longer than intended. Fixed in 1.4.2.

References:

https://github.com/hashicorp/vault/blob/master/CHANGELOG.md#142-may-21st-2020
https://www.hashicorp.com/blog/category/vault/


Note You need to log in before you can comment on or make changes to this bug.