CVE-2021-38554

Related Vulnerabilities: CVE-2021-38554  

HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser. Fixed in 1.8.0 and pending 1.7.4 / 1.6.6 releases.

Description

The MITRE CVE dictionary describes this issue as:

HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser. Fixed in 1.8.0 and pending 1.7.4 / 1.6.6 releases.

Additional Information

  • Bugzilla 1995207: CVE-2021-38554 vault: UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
  • FAQ: Frequently asked questions about CVE-2021-38554