Related Vulnerabilities: CVE-2021-3282  

HashiCorp Vault Enterprise 1.6.0 and 1.6.1 allowed the `remove-peer` raft operator command to be executed against DR secondaries without authentication. This is fixed in version 1.6.2.

Severity Medium

Remote Yes

Type Authentication bypass

Description

HashiCorp Vault Enterprise 1.6.0 and 1.6.1 allowed the `remove-peer` raft operator command to be executed against DR secondaries without authentication. This is fixed in version 1.6.2.

AVG-1519 vault 1.5.4-1 Medium Not affected

https://discuss.hashicorp.com/t/hcsec-2021-04-vault-enterprise-s-dr-secondaries-allowed-raft-peer-removal-without-authentication/20337