chore(deps): bump github.com/hashicorp/vault/api from 1.9.0 to 1.9.1 in /vaultserver
Created by: dependabot[bot]
Bumps github.com/hashicorp/vault/api from 1.9.0 to 1.9.1.
Release notes
Sourced from github.com/hashicorp/vault/api's releases.
v1.9.1
1.9.1
December 9, 2021
IMPROVEMENTS:
- storage/aerospike: Upgrade
aerospike-client-go
to v5.6.0. [GH-12165]BUG FIXES:
- auth/approle: Fix regression where unset cidrlist is returned as nil instead of zero-length array. [GH-13235]
- ha (enterprise): Prevents performance standby nodes from serving and caching stale data immediately after performance standby election completes
- http:Fix /sys/monitor endpoint returning streaming not supported [GH-13200]
- identity/oidc: Make the
nonce
parameter optional for the Authorization Endpoint of OIDC providers. [GH-13231]- identity: Fixes a panic in the OIDC key rotation due to a missing nil check. [GH-13298]
- sdk/queue: move lock before length check to prevent panics. [GH-13146]
- secrets/azure: Fixes service principal generation when assigning roles that have DataActions. [GH-13277]
- secrets/pki: Recognize ed25519 when requesting a response in PKCS8 format [GH-13257]
- storage/raft: Fix a panic when trying to store a key > 32KB in a transaction. [GH-13286]
- storage/raft: Fix a panic when trying to write a key > 32KB [GH-13282]
- ui: Do not show verify connection value on database connection config page [GH-13152]
- ui: Fixes issue restoring raft storage snapshot [GH-13107]
- ui: Fixes issue with OIDC auth workflow when using MetaMask Chrome extension [GH-13133]
- ui: Fixes issue with automate secret deletion value not displaying initially if set in secret metadata edit view [GH-13177]
- ui: Fixes issue with placeholder not displaying for automatically deleted secrets when deletion time has passed [GH-13166]
- ui: Fixes node-forge error when parsing EC (elliptical curve) certs [GH-13238]
Changelog
Sourced from github.com/hashicorp/vault/api's changelog.
1.9.10
September 30, 2022
SECURITY:
- secrets/pki: Vault’s TLS certificate auth method did not initially load the optionally-configured CRL issued by the role’s CA into memory on startup, resulting in the revocation list not being checked, if the CRL has not yet been retrieved. This vulnerability, CVE-2022-41316, is fixed in Vault 1.12.0, 1.11.4, 1.10.7, and 1.9.10. [HSEC-2022-24]
BUG FIXES:
- auth/cert: Vault does not initially load the CRLs in cert auth unless the read/write CRL endpoint is hit. [GH-17138]
- replication (enterprise): Fix data race in SaveCheckpoint()
- ui: Fix lease force revoke action [GH-16930]
1.9.9
August 31, 2022
SECURITY:
- core: When entity aliases mapped to a single entity share the same alias name, but have different mount accessors, Vault can leak metadata between the aliases. This metadata leak may result in unexpected access if templated policies are using alias metadata for path names. This vulnerability, CVE-2022-40186, is fixed in 1.11.3, 1.10.6, and 1.9.9. [HSEC-2022-18]
CHANGES:
- core: Bump Go version to 1.17.13.
BUG FIXES:
- core (enterprise): Fix some races in merkle index flushing code found in testing
- core: Increase the allowed concurrent gRPC streams over the cluster port. [GH-16327]
- database: Invalidate queue should cancel context first to avoid deadlock [GH-15933]
- secrets/database: Fix a bug where the secret engine would queue up a lot of WAL deletes during startup. [GH-16686]
- ui: Fix OIDC callback to accept namespace flag in different formats [GH-16886]
- ui: Fix issue logging in with JWT auth method [GH-16466]
SECURITY:
- identity/entity: When entity aliases mapped to a single entity share the same alias name, but have different mount accessors, Vault can leak metadata between the aliases. This metadata leak may result in unexpected access if templated policies are using alias metadata for path names. [HCSEC-2022-18]
1.9.8
July 21, 2022
SECURITY:
- storage/raft: Vault Enterprise (“Vault”) clusters using Integrated Storage expose an unauthenticated API endpoint that could be abused to override the voter status of a node within a Vault HA cluster, introducing potential for future data loss or catastrophic failure. This vulnerability, CVE-2022-36129, was fixed in Vault 1.9.8, 1.10.5, and 1.11.1. [HSEC-2022-15]
CHANGES:
- core: Bump Go version to 1.17.12.
IMPROVEMENTS:
... (truncated)
Commits
-
3d69cbb
GetCredentials Bug fix (#13336) (#13337) -
ab20565
Updating go.mod with SDK version bump for 1.9.1 (#13314) -
dba5a5d
KV spelling error on destroy (#13313) (#13315) -
775834e
Updating version in SDK for 1.9.1 (#13302) -
50e7a94
version test robustness backports (#13311) -
5f98886
Identity: check NextSigningKey existence during key rotation (#13298) (#13303) -
90e1bca
Aerospike backend update (#12165) (#13296) -
e36348b
sdk/queue: move lock before checking queue length (#13146) (#13297) -
8d2b80c
Backport 1.9.x: secrets/azure: Update plugin to v0.11.2 (#13277) (#13294) -
cb06696
Prevent raft transactions from containing overlarge keys. (#13286) (#13288) - Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)