
Cloud Vulnerability DB
A community-led vulnerabilities database
HashiCorp vault-ssh-helper up to and including version 0.1.6 contained a security vulnerability where the helper incorrectly accepted Vault-issued SSH OTPs (One-Time Passwords) for the subnet in which a host's network interface was located, rather than validating against the specific IP address assigned to that interface. This vulnerability was discovered and disclosed in August 2020, affecting all versions up to and including 0.1.6 (HashiCorp Changelog, NVD).
The vulnerability has been assigned a CVSS v3.1 base score of 7.5 (HIGH) with vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N. The issue stems from improper input validation (CWE-20) where the helper failed to properly verify the specific IP address of the host interface, instead accepting OTPs valid for the entire subnet (NVD).
The vulnerability could allow an attacker to use valid OTPs intended for one specific host to gain unauthorized SSH access to other hosts within the same subnet, potentially leading to unauthorized access across multiple systems (NVD).
The vulnerability requires network access to the affected systems and a valid OTP for any host within the target subnet. No specific exploit code or evidence of active exploitation in the wild has been publicly reported.
The vulnerability was fixed in version 0.2.0 of vault-ssh-helper, released on August 19, 2020. Users should upgrade to version 0.2.0 or later to address this security issue (HashiCorp Changelog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."