-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/hashicorp/vault | go | >= 1.17.3, < 1.17.5 | 1.17.5 |
The vulnerability stems from improper storage writes on performance standby nodes during auth/secrets engine remount operations. The patches add conditional guards (updateStorage) to prevent these writes. The vulnerable functions are the unguarded versions of remountCredential and remountSecretsEngine that would appear in profilers when storage persistence is attempted on standby nodes, which could trigger audit logging of plaintext tokens before HMAC protection was re-added.
Ongoing coverage of React2Shell