CVE-2021-38553

MEDIUM

HashiCorp Vault <1.8.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0.

References (2)

Core 2

Scores

CVSS v3 4.4
EPSS 0.0027
EPSS Percentile 18.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-281
Status published
Products (2)
hashicorp/vault 1.4.0 - 1.8.0 (2 CPE variants)
hashicorp/vault 1.4.0 - 1.8.0Go
Published Aug 13, 2021
Tracked Since Feb 18, 2026