Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.
← back | CVE Intelligence

CVE-2020-16250

Curated 2 security research writeups, vulnerability advisories and exploitation analyses for CVE-2020-16250.

Coverage Span
2020-10-06 → 2025-06-18
Reports
2 related reports

Associated Reports & Timeline

2.
projectzero.google | vulnerability | | original ↗ | #cloud | #aws | #authentication | #cve
In this blog post I'll discuss two vulnerabilities in HashiCorp Vault and its integration with Amazon Web Services (AWS) and Google Cloud Platform (GCP). These issues can lead to an authentication bypass in configurations that use the aws and gcp auth methods, and demonstrate the type of issues you can find in modern “cloud-native” software. Both vulnerabilities (CVE-2020-16250/16251) were addressed by HashiCorp and are fixed in Vault versions 1.2.5, 1.3.8, 1.4.4 and 1.5.1 released in August.