HIGH 7.4 Go

Invalid session token expiration

GHSA-38j9-7pp9-2hjw · BIT-vault-2021-32923 · CVE-2021-32923 · GO-2022-0623

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.

Ready to move

Start Securing

Free, no credit card | First findings in minutes