Token Lease Renewal Issue in HashiCorp Vault and Vault Enterprise
CVE-2021-32923
7.4HIGH
What is CVE-2021-32923?
HashiCorp Vault and Vault Enterprise have a vulnerability that permits the renewal of nearly-expired token leases and dynamic secret leases—specifically those within 1 second of their maximum time-to-live (TTL). This mismanagement leads to these tokens being erroneously categorized as non-expiring during future transactions. The issue affects multiple versions and can result in unintended access privileges if not addressed. The vulnerability has been resolved in versions 1.5.9, 1.6.5, and 1.7.2.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved