{"id":"CVE-2020-24359","aliases":["GHSA-f9fq-vjvh-779p","GO-2022-0824"],"url":"https://o3.security/vulnerability/CVE-2020-24359","summary":"Improper Input Validation in vault-ssh-helper","details":"HashiCorp vault-ssh-helper up to and including version 0.1.6 incorrectly accepted Vault-issued SSH OTPs for the subnet in which a host's network interface was located, rather than the specific IP address assigned to that interface. Fixed in 0.2.0.","published":"2020-08-20T17:15:10.977Z","modified":"2026-07-08T20:29:38.071802Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/hashicorp/vault-ssh-helper","fixedVersion":"0.2.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/hashicorp/vault-ssh-helper/blob/master/CHANGELOG.md#020-august-19-2020"},{"type":"ADVISORY","url":"https://github.com/hashicorp/vault-ssh-helper/releases"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T20:29:38.071802Z"}}