HIGH 7.4 Go
Invalid session token expiration
GHSA-38j9-7pp9-2hjw · BIT-vault-2021-32923 · CVE-2021-32923 · GO-2022-0623
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.
Ready to move
Start Securing
Free, no credit card | First findings in minutes