PT-2023-26093 · Hashicorp+1 · Vault Enterprise+1

Marc Billow

·

Publicado

2023-09-28

·

Atualizado

2024-09-26

·

CVE-2023-3775

CVSS v3.1

4.9

Média

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Vault Enterprise versions prior to 1.15.0 Vault Enterprise versions prior to 1.14.4 Vault Enterprise versions prior to 1.13.8
Description A Vault Enterprise Sentinel Role Governing Policy created by an operator to restrict access to resources in one namespace can be applied to requests outside in another non-descendant namespace, potentially resulting in denial of service.
Recommendations For Vault Enterprise versions prior to 1.15.0, update to version 1.15.0 or later. For Vault Enterprise versions prior to 1.14.4, update to version 1.14.4 or later. For Vault Enterprise versions prior to 1.13.8, update to version 1.13.8 or later.

Correção

DoS

Incorrect Privilege Assignment

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2024-3459
ALT-PU-2024-3678
ALT-PU-2024-4187
BIT-VAULT-2023-3775
CVE-2023-3775

Produtos afetados

Alt Linux
Vault Enterprise