HashiCorp Vault improper configuration of multi factor authentication
Moderate severity
GitHub Reviewed
Published
May 18, 2022
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Package
Affected versions
>= 1.10.0, < 1.10.3
Patched versions
1.10.3
Description
Published by the National Vulnerability Database
May 17, 2022
Published to the GitHub Advisory Database
May 18, 2022
Reviewed
May 25, 2022
Last updated
Jan 29, 2023
HashiCorp Vault and Vault Enterprise from 1.10.0 to 1.10.2 did not correctly configure and enforce MFA on login after server restarts. This affects the Login MFA feature introduced in Vault and Vault Enterprise 1.10.0 and does not affect the separate Enterprise MFA feature set. Fixed in 1.10.3.
References