CVE-2021-38553

Related Vulnerabilities: CVE-2021-38553  

HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0.

Description

The MITRE CVE dictionary describes this issue as:

HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0.

Additional Information

  • Bugzilla 1995209: CVE-2021-38553 vault: Underlying database file with excessively broad filesystem permissions
  • CWE-276: Incorrect Default Permissions
  • FAQ: Frequently asked questions about CVE-2021-38553