Home
MEDIUM: 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NDefault status
unaffected
Any version before 1.20.1
affected
Default status
unaffected
Any version before 1.20.1
affected
Description
Vault and Vault Enterprise’s (“Vault”) TOTP Secrets Engine code validation endpoint is susceptible to code reuse within its validity period. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Problem types
CWE-156: Improper Neutralization of Whitespace
Product status
Any version before 1.20.1
Any version before 1.20.1
References
discuss.hashicorp.com/...otp-secrets-engine-code-reuse/76036