PT-2023-26093 · Hashicorp+1 · Vault Enterprise+1
Marc Billow
·
Publicado
2023-09-28
·
Atualizado
2024-09-26
·
CVE-2023-3775
CVSS v3.1
4.9
Média
| Vetor | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Vault Enterprise versions prior to 1.15.0
Vault Enterprise versions prior to 1.14.4
Vault Enterprise versions prior to 1.13.8
Description
A Vault Enterprise Sentinel Role Governing Policy created by an operator to restrict access to resources in one namespace can be applied to requests outside in another non-descendant namespace, potentially resulting in denial of service.
Recommendations
For Vault Enterprise versions prior to 1.15.0, update to version 1.15.0 or later.
For Vault Enterprise versions prior to 1.14.4, update to version 1.14.4 or later.
For Vault Enterprise versions prior to 1.13.8, update to version 1.13.8 or later.
Correção
DoS
Incorrect Privilege Assignment
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Vault Enterprise