HashiCorp Vault and Vault Enterprise allowed for enumeration of Secrets Engine mount paths via unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7.
{ "cpes": [ "cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*", "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*" ], "severity": "Medium" }