cve/2020/CVE-2020-25594.md
2024-05-25 21:48:12 +02:00

650 B

CVE-2020-25594

Description

HashiCorp Vault and Vault Enterprise allowed for enumeration of Secrets Engine mount paths via unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7.

POC

Reference

No PoCs from references.

Github