HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.
{ "cpes": [ "cpe:2.3:a:hashicorp:vault:*:*:*:*:-:*:*:*", "cpe:2.3:a:hashicorp:vault:*:*:*:*:enterprise:*:*:*" ], "severity": "High" }