CVE-2021-3282
HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the `remove-peer` raft operator command to be executed against DR secon
HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the remove-peer raft operator command to be executed against DR secondaries without authentication. Fixed in 1.6.2.
HIGH · CVSS 7.5
EPSS 0.00316
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules1
YARA rules0