{"id":"GHSA-f9fq-vjvh-779p","summary":"Improper Input Validation in vault-ssh-helper","details":"HashiCorp vault-ssh-helper (github.com/hashicorp/vault-ssh-helper/helper) up to and including version 0.1.6 incorrectly accepted Vault-issued SSH OTPs for the subnet in which a host's network interface was located, rather than the specific IP address assigned to that interface. Fixed in 0.2.0.","aliases":["CVE-2020-24359","GO-2022-0824"],"modified":"2024-08-21T15:57:13.968021Z","published":"2022-02-15T01:57:18Z","database_specific":{"cwe_ids":["CWE-20"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-05-12T20:21:27Z","nvd_published_at":null},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-24359"},{"type":"WEB","url":"https://github.com/hashicorp/vault-ssh-helper/commit/83effd08cbcbe4b993d776bd9b39465cd9e4603f"},{"type":"WEB","url":"https://github.com/hashicorp/vault-ssh-helper/blob/master/CHANGELOG.md#020-august-19-2020"},{"type":"WEB","url":"https://github.com/hashicorp/vault-ssh-helper/releases"}],"affected":[{"package":{"name":"github.com/hashicorp/vault-ssh-helper","ecosystem":"Go","purl":"pkg:golang/github.com/hashicorp/vault-ssh-helper"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.2.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-f9fq-vjvh-779p/GHSA-f9fq-vjvh-779p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}