Zum Inhalt springen
Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Hashicorp Vault von Hashicorp

Vault 2.1.1

Vault 2.1.1 behebt Sicherheitslücken durch Updates von apache/thrift, golang.org/x/crypto und google.golang.org/grpc, ergänzt einen Okta-Provider für auth/jwt mit Gruppenabruf über die Admin API, begrenzt gleichzeitige Raft-Retry-Join-Worker auf 20 und enthält Verbesserungen bei Secrets Import und PKI-Widerruf sowie Fehlerbehebungen.

2.1.1

September 16, 2026

SECURITY:

  • core: Update github.com/apache/thrift to v0.24.0 to fix security vulnerability ghsa-8wv5-x4w7-5gww.
  • core: Update golang.org/x/crypto to v0.56.0 to fix security vulnerabilities GO-2026-6354 and GO-2026-6355.
  • core: Update google.golang.org/grpc to v1.83.2 to fix security vulnerability GHSA-2v4p-qf9q-27wj.

CHANGES:

  • auth/jwt: Added Okta provider with group fetching from Admin API when fetch_groups=true and truncation is detected.
  • auth/jwt: Update plugin to v0.26.4
  • core/raft: Limited concurrent retry-join workers to 20. Any further retry-join attempts while 20 are in progress will result in an error (too many concurrent raft retry joins in progress).
  • core: Bump Go version to 1.26.8

IMPROVEMENTS:

  • secrets import: Add allowed_ipv4_cidrs to source_aws and source_azure Secrets Import blocks to allow private CIDR exemptions for SSRF-safe connectivity.
  • secrets/pki: add an additional field to include an RFC 5280 revocation reason for (/pki/revoke) and (/pki/revoke-with-key).
  • ui: Bump dompurify to 3.4.15 to address SECVULN advisories

BUG FIXES:

  • Secrets Recovery (enterprise): Fixing Vault panic in cli when running vault recover without a path.
  • auth/jwt: Fixed incorrect HTTP status codes returned during agent ceiling policy evaluation. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Hashicorp Vault von Hashicorp

Vault 2.1.0

Vault 2.1.0 aktualisiert etcd client und go-pkcs12 zur Behebung von Sicherheitslücken, ergänzt die Lizenzbedingungen um Agentic IAM und macht issuer_id sowie unique_id_claim von OAuth-Resource-Server-Profilen (Enterprise) nach der Erstellung unveränderbar, wobei die Funktion keine Aktivierung über den Endpunkt sys/activation-flags/oauth-resource-server/activate mehr benötigt.

2.1.0

September 01, 2026

SECURITY:

  • core: Update go.etcd.io/etcd/client/pkg/v3 to v3.7.1 to fix security vulnerability GO-2026-6107.
  • core: Update software.sslmate.com/src/go-pkcs12 to v0.7.2 to fix security vulnerability GO-2026-5052.

CHANGES:

  • License: Add Agentic IAM terms to client licensing model and update terms for Vault Platform licensing model.
  • core: Bump Go version to 1.26.7.
  • oauth-resource-server (enterprise): Prevent issuer_id from being mutated after OAuth Resource Server profile creation. Operators must delete and recreate profiles to change the issuer_id.
  • oauth-resource-server (enterprise): Prevent unique_id_claim from being mutated after OAuth Resource Server profile creation. Operators must delete and recreate profiles to change the unique_id_claim.
  • oauth-resource-server (enterprise): The OAuth Resource Server feature no longer requires activation via the sys/activation-flags/oauth-resource-server/activate endpoint.
  • oauth-resource-server (enterprise): Update OAuth Resource Server config to include custom claim options for the token's unique identifier and actor.
  • secrets/openldap (enterprise): Update plugin to v0.18.4+ent

FEATURES: …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Hashicorp Vault von Hashicorp

Vault 2.0.4

Vault 2.0.4 behebt mehrere Sicherheitslücken, darunter eine Rechteausweitung durch Groß-/Kleinschreibung bei Policy-Namen in denied_parameters, und entfernt gnupg, openssl und procps aus den UBI-basierten Container-Images.

2.0.4

August 04, 2026

BREAKING CHANGES:

  • containers: The following packages have been removed from UBI based container images: gnupg, openssl, procps.

SECURITY:

  • acl: Fix privilege-escalation vulnerability where a denied_parameters constraint on the policies request field could be bypassed by submitting a mixed-case policy name (e.g. "Super-Admin" instead of "super-admin"). Vault now normalizes the policies parameter to lowercase before evaluating allowed_parameters/denied_parameters constraints.
  • identity/scim (enterprise): The identity/entity/merge endpoint now rejects requests that involve any SCIM-managed entity, preventing privileged operators from bypassing SCIM ownership guardrails to transfer aliases, group memberships, or policies across SCIM boundaries.
  • identity: Prevent the entity batch-delete endpoint (identity/entity/batch-delete) from deleting the underlying storage of entities that belong to another namespace.
  • identity: entity/name updates now reject mismatched id or external_id selectors to prevent retargeting updates to a different entity

CHANGES:

  • auth/oci: Update plugin to v0.21.3
  • core: Bump Go version to 1.26.5.
  • core: remove support for duplicate attributes in HCL configuration files and policy definitions. Parsing HCL with …

Originalquelle(öffnet in neuem Tab)Problem melden