A timing side channel in Vault and Vault Enterprise’s (“Vault”) userpass auth method allowed an attacker to distinguish between existing and non-existing users, and potentially enumerate valid usernames for Vault’s Userpass auth method. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Details
A timing side channel in Vault and Vault Enterprise’s (“Vault”) userpass auth method allowed an attacker to distinguish between existing and non-existing users, and potentially enumerate valid usernames for Vault’s Userpass auth method. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Statement
Subscribe to updates
Product 1
Loading products...
No products found
Loading...
No matches
Unsubscribe
Enter your email and we'll send you a link to manage your subscription preferences.
Check your inbox
If this email is subscribed, we've sent a link to manage your preferences.
Contact us
Message Delivered!
Thanks for reaching out!
The TuxCare team has received your message and will get back to you shortly.