Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 727660 (CVE-2020-12757, CVE-2020-13223) - <app-admin/vault-1.4.2: Multiple vulnerabilities (CVE-2020-{13223,12757})
Summary: <app-admin/vault-1.4.2: Multiple vulnerabilities (CVE-2020-{13223,12757})
Status: RESOLVED FIXED
Alias: CVE-2020-12757, CVE-2020-13223
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B4 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2020-06-09 13:40 UTC by Sam James
Modified: 2020-07-26 05:25 UTC (History)
1 user (show)

See Also:
Package list:
=app-admin/vault-1.4.2-r1
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-06-09 13:40:35 UTC
* CVE-2020-13223

Description:
"core: Proxy environment variables are now redacted before being logged, in case the URLs include a username:password."

PR: https://github.com/hashicorp/vault/pull/9022

* CVE-2020-12757

Description:
"secrets/gcp: Fix a regression in 1.4.0 where the system TTLs were being used instead of the configured backend TTLs for dynamic service accounts."

PR: https://github.com/hashicorp/vault-plugin-secrets-gcp/pull/85
Comment 1 Larry the Git Cow gentoo-dev 2020-06-11 03:57:02 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=d4d78ad8a53af7da57f8995560480724a77c327a

commit d4d78ad8a53af7da57f8995560480724a77c327a
Author:     Zac Medico <zmedico@gentoo.org>
AuthorDate: 2020-06-11 03:55:16 +0000
Commit:     Zac Medico <zmedico@gentoo.org>
CommitDate: 2020-06-11 03:55:41 +0000

    app-admin/vault: Bump to version 1.4.2 (bug 727660)
    
    Bug: https://bugs.gentoo.org/727660
    Package-Manager: Portage-2.3.100, Repoman-2.3.22
    Signed-off-by: Zac Medico <zmedico@gentoo.org>

 app-admin/vault/Manifest           |  2 ++
 app-admin/vault/vault-1.4.2.ebuild | 72 ++++++++++++++++++++++++++++++++++++++
 2 files changed, 74 insertions(+)
Comment 2 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-06-11 04:04:26 UTC
@maintainer(s), let us know when ready for stabilisation, or call yourself
Comment 3 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-06-16 13:29:04 UTC
@maintainer(s), I'll add CC-ARCHES now if no objections.
Comment 4 Agostino Sarubbo gentoo-dev 2020-06-21 16:56:20 UTC
amd64 stable.

Maintainer(s), please cleanup.
Security, please vote.
Comment 5 Larry the Git Cow gentoo-dev 2020-06-25 20:17:38 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=0c571fb781d73c1b773e3e033cf192be29de1ab8

commit 0c571fb781d73c1b773e3e033cf192be29de1ab8
Author:     William Hubbs <williamh@gentoo.org>
AuthorDate: 2020-06-25 20:08:04 +0000
Commit:     William Hubbs <williamh@gentoo.org>
CommitDate: 2020-06-25 20:17:06 +0000

    app-admin/vault: remove old
    
    Bug: https://bugs.gentoo.org/727660
    Signed-off-by: William Hubbs <williamh@gentoo.org>

 app-admin/vault/Manifest           |  2 --
 app-admin/vault/vault-1.4.0.ebuild | 72 --------------------------------------
 2 files changed, 74 deletions(-)
Comment 6 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-06-25 20:19:04 UTC
Thanks!
Comment 7 NATTkA bot gentoo-dev 2020-06-26 00:48:34 UTC
Unable to check for sanity:

> no match for package: =app-admin/vault-1.4.2
Comment 8 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-07-26 05:25:03 UTC
GLSA vote: no!

Closing.