Intel

AIKIDO-2024-10302

github.com/hashicorp/vault is vulnerable to Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Sep 30, 2024

85

High Risk

This Affects:

gogithub.com/hashicorp/vault
1.16.0 - 1.16.3
1.17.0 - 1.17.5
Fixed in 1.17.6
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to a race condition while storing static secret response into the cache. This is very unwanted given the security sensitivity of this package.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/hashicorp/vault is vulnerable to Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in versions 1.16.0 - 1.16.3 and 1.17.0 - 1.17.5.

How to fix this

Upgrade the github.com/hashicorp/vault library to the patch version.