{"id":"CVE-2021-38554","title":"vault: UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser (CVE-2021-38554)","summary":"A flaw was found in the vault package. The Vault UI web application may fail to completely clear a client-side data cache on user logout. As a result, an authenticated user sharing a browser to access Vault may have been able to view the p…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","cvssSource":"vendor","cwe":"CWE-200","vendor":"Red Hat","product":"Red Hat Openshift Container Storage 4","affected":["openshift_container_platform 4","openshift_container_storage 4"],"patched":["github.com/hashicorp/vault 1.6.6","github.com/hashicorp/vault 1.7.4"],"published":"2021-08-13","updated":"2026-09-17","sourceUpdated":"2026-09-17T14:02:21+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-38554.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-38554.json"},{"url":"https://access.redhat.com/security/cve/CVE-2021-38554"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1995207"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-38554"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-38554"},{"url":"https://discuss.hashicorp.com/t/hcsec-2021-19-vault-s-ui-cached-user-viewed-secrets-between-shared-browser-sessions/28166"},{"url":"https://github.com/hashicorp/vault"},{"url":"https://github.com/hashicorp/vault/releases/tag/v1.6.6"},{"url":"https://github.com/hashicorp/vault/releases/tag/v1.7.4"},{"url":"https://security.gentoo.org/glsa/202207-01"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.00911,"epssPercentile":0.57955,"aliases":["GHSA-6239-28c2-9mrm","BIT-vault-2021-38554","GO-2022-0632"],"ecosystem":"go","ingestedAt":"2026-09-12T03:13:01.757Z","slug":"CVE-2021-38554","body":"## Overview\n\nA flaw was found in the vault package. The Vault UI web application may fail to completely clear a client-side data cache on user logout. As a result, an authenticated user sharing a browser to access Vault may have been able to view the previous authenticated user’s cached secrets, even if they were not authorized by Vault policies to view them.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Low · affected: Red Hat OpenShift Container Platform 4, Red Hat Openshift Container Storage 4 · no fix planned: Red Hat Openshift Container Storage 4, Red Hat OpenShift Container Platform 4 · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-38554.json)\n\n**vault: UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser** — rated Low by Red Hat. Released 2021-08-13, updated 2026-09-17.\n\nAffected:\n\n- Red Hat OpenShift Container Platform 4\n- Red Hat Openshift Container Storage 4\n\nNo fix planned:\n\n- Red Hat Openshift Container Storage 4\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Logging Subsystem for Red Hat OpenShift\n- OpenShift Service Mesh 2.0\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Openshift Data Foundation 4\n\n## Remediation\n\nOut of support scope\n\n## Package advisory (CVE-2021-38554)\n\nAffected packages:\n\n- `github.com/hashicorp/vault < 1.6.6`\n- `github.com/hashicorp/vault >= 1.7.0, < 1.7.4`\n\nPatched in:\n\n- `github.com/hashicorp/vault 1.6.6`\n- `github.com/hashicorp/vault 1.7.4`\n\nSource: https://osv.dev/vulnerability/GHSA-6239-28c2-9mrm","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}