{"id":"CVE-2021-32923","title":"vault: Token leases incorrectly treated as non-expiring (CVE-2021-32923)","summary":"A flaw was found in the HashiCorp Vault and Vault Enterprise. The vault could allow a remote attacker to bypass security restrictions caused by a renewal logic flaw when a token lease or dynamic secret lease was renewed inside the last sec…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","cvssSource":"vendor","cwe":"CWE-613","vendor":"Red Hat","product":"Red Hat Openshift Container Storage 4","affected":["openshift_container_storage 4"],"patched":["github.com/hashicorp/vault 1.7.2","github.com/hashicorp/vault 1.6.5","github.com/hashicorp/vault 1.5.9"],"published":"2021-06-03","updated":"2026-09-17","sourceUpdated":"2026-09-17T14:01:27+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-32923.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-32923.json"},{"url":"https://access.redhat.com/security/cve/CVE-2021-32923"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1968032"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-32923"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-32923"},{"url":"https://discuss.hashicorp.com/t/hcsec-2021-15-vault-renewed-nearly-expired-leases-with-incorrect-non-expiring-ttls/24603"},{"url":"https://security.gentoo.org/glsa/202207-01"},{"url":"https://www.hashicorp.com/blog/category/vault"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.01376,"epssPercentile":0.70429,"aliases":["GHSA-38j9-7pp9-2hjw","BIT-vault-2021-32923","GO-2022-0623"],"ecosystem":"go","scores":{"vendor":6.5,"osv":7.4},"ingestedAt":"2026-09-12T03:13:01.748Z","slug":"CVE-2021-32923","body":"## Overview\n\nA flaw was found in the HashiCorp Vault and Vault Enterprise. The vault could allow a remote attacker to bypass security restrictions caused by a renewal logic flaw when a token lease or dynamic secret lease was renewed inside the last second of its maximum TTL. By sending a specially crafted request, an attacker can bypass authentication validation and gain access to the system.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Openshift Container Storage 4 · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-32923.json)\n\n**vault: Token leases incorrectly treated as non-expiring** — rated Moderate by Red Hat. Released 2021-06-03, updated 2026-09-17.\n\nAffected:\n\n- Red Hat Openshift Container Storage 4\n\nNot affected:\n\n- Logging Subsystem for Red Hat OpenShift\n- OpenShift Service Mesh 2.0\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat OpenShift Container Platform 4\n- Red Hat Openshift Data Foundation 4\n\n## Remediation\n\nRefer to the advisory for fix availability.\n\n## Package advisory (CVE-2021-32923)\n\nAffected packages:\n\n- `github.com/hashicorp/vault >= 1.7.0, < 1.7.2`\n- `github.com/hashicorp/vault >= 1.6.0, < 1.6.5`\n- `github.com/hashicorp/vault >= 0.10.0, < 1.5.9`\n\nPatched in:\n\n- `github.com/hashicorp/vault 1.7.2`\n- `github.com/hashicorp/vault 1.6.5`\n- `github.com/hashicorp/vault 1.5.9`\n\nSource: https://osv.dev/vulnerability/GHSA-38j9-7pp9-2hjw","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[{"seq":206312,"id":"CVE-2021-32923","ts":1789663201183,"field":"cvss","old":"7.4","new":"6.5"},{"seq":206311,"id":"CVE-2021-32923","ts":1789663201183,"field":"severity","old":"high","new":"medium"}]}