The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade github.com/hashicorp/vault/vault to version 2.0.0 or higher.
github.com/hashicorp/vault/vault is a tool for securely accessing secrets.
Affected versions of this package are vulnerable to Insertion of Sensitive Information Into Sent Data through the CheckToken request handling in vault/request_handling.go. An attacker can cause Vault to forward a request containing a Vault bearer token in the Authorization header to a plugin backend by sending a request to a mount or auth method configured to passthrough that header. The backend receives the Vault token alongside any other authorization values, exposing credentials to the plugin and allowing the token to be reused or logged by code that should not see it.
Notes
Authorization in passthrough_request_headers; deployments that do not opt into that header passthrough are not exposed by this issue.Authorization header.