CVE-2020-25594
CVE-2020-25594
HashiCorp Vault and Vault Enterprise allowed for enumeration of Secrets Engine mount paths via unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →