PT-2023-17999 · Hashicorp+1 · Hashicorp Vault+1

Michal Zaczek

·

Publicado

2023-06-09

·

Atualizado

2025-05-26

·

CVE-2023-2121

CVSS v2.0

5.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Hashicorp Vault versions prior to 1.11.11 Hashicorp Vault versions prior to 1.12.7 Hashicorp Vault versions prior to 1.13.3 Hashicorp Vault versions prior to 1.14.0
Description The key-value v2 (kv-v2) diff viewer in Vault allowed HTML injection into the Vault web UI through key values.
Recommendations For versions prior to 1.11.11, update to version 1.11.11 or later. For versions prior to 1.12.7, update to version 1.12.7 or later. For versions prior to 1.13.3, update to version 1.13.3 or later. For versions prior to 1.14.0, update to version 1.14.0 or later.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-06183
BIT-VAULT-2023-2121
CVE-2023-2121
GHSA-GQ98-53RQ-QR5H
GO-2023-1849

Produtos afetados

Hashicorp Vault
Red Os