MEDIUM 5.3 Go

Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault

GHSA-6239-28c2-9mrm · BIT-vault-2021-38554 · CVE-2021-38554 · GO-2022-0632

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser. Fixed in 1.8.0 and pending 1.7.4 / 1.6.6 releases.

Ready to move

Start Securing

Free, no credit card | First findings in minutes