If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
| Vendor | Product | Versions |
|---|---|---|
| hashi | vault | 0.11.2, 0.11.2 |
Updated description with new details, changed vendor to 'hashicorp', added product 'vault enterprise', included new affected version '1.21.0', updated severity to 'MEDIUM', and marked as actively exploited.
Initial creation