HIGH 7.5 Go
Improper Resource Shutdown or Release in HashiCorp Vault
GHSA-9vh5-r4qw-v3vv · BIT-vault-2020-7220 · CVE-2020-7220 · GO-2022-0816
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails, in certain circumstances, to revoke dynamic secrets for a mount in a deleted namespace. Fixed in 1.3.2.
Ready to move
Start Securing
Free, no credit card | First findings in minutes