CVE-2021-3282 is a high-severity vulnerability affecting HashiCorp Vault Enterprise versions 1.6.0 and 1.6.1, allowing unauthenticated execution of the "remove-peer" raft operator command on DR secondaries. With a CVSS score of 7.5, this network-exploitable flaw has low attack complexity and could lead to high integrity impacts, specifically the removal of a peer from the Raft cluster without authorization. While no public exploits, Metasploit modules, or Nuclei templates are available, and community discussion is minimal, the vulnerability was patched in Vault Enterprise 1.6.2.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.6.0CPE matchmatch criteria | cpe:2.3:a:hashicorp:vault:1.6.0:*:*:*:*:*:*:* | ||
1.6.1CPE matchmatch criteria | cpe:2.3:a:hashicorp:vault:1.6.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.