From 254c716d0dd35a6846f281fd4a3eaf970dc0bede Mon Sep 17 00:00:00 2001 From: GLSAMaker Date: Fri, 29 Jul 2022 21:22:59 +0000 Subject: [ GLSA-202207-01 ] HashiCorp Vault: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/768312 Bug: https://bugs.gentoo.org/797244 Bug: https://bugs.gentoo.org/808093 Bug: https://bugs.gentoo.org/817269 Bug: https://bugs.gentoo.org/827945 Bug: https://bugs.gentoo.org/829493 Bug: https://bugs.gentoo.org/835070 Bug: https://bugs.gentoo.org/845405 Signed-off-by: GLSAMaker Signed-off-by: John Helmert III --- glsa-202207-01.xml | 61 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 61 insertions(+) create mode 100644 glsa-202207-01.xml diff --git a/glsa-202207-01.xml b/glsa-202207-01.xml new file mode 100644 index 00000000..ecb32ade --- /dev/null +++ b/glsa-202207-01.xml @@ -0,0 +1,61 @@ + + + + HashiCorp Vault: Multiple Vulnerabilities + Multiple vulnerabilities have been discovered in HashiCorp Vault, the worst of which could result in denial of service. + vault + 2022-07-29 + 2022-07-29 + 768312 + 797244 + 808093 + 817269 + 827945 + 829493 + 835070 + 845405 + remote + + + 1.10.3 + 1.10.3 + + + +

HashiCorp Vault is a tool for managing secrets.

+
+ +

Multiple vulnerabilities have been discovered in HashiCorp Vault. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All HashiCorp Vault users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-admin/vault-1.10.3" + +
+ + CVE-2020-25594 + CVE-2021-27668 + CVE-2021-3024 + CVE-2021-3282 + CVE-2021-32923 + CVE-2021-37219 + CVE-2021-38553 + CVE-2021-38554 + CVE-2021-41802 + CVE-2021-43998 + CVE-2021-45042 + CVE-2022-25243 + CVE-2022-30689 + + ajak + ajak +
\ No newline at end of file -- cgit v1.2.3-65-gdbad