PT-2023-9289 · Hashicorp+1 · Hashicorp Vault+2

CVE-2023-5077

·

Publicado

2023-09-28

·

Atualizado

2024-09-26

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions HashiCorp Vault versions prior to 1.13.0
Description The issue is related to the Google Cloud secrets engine in HashiCorp Vault and Vault Enterprise, where existing Google Cloud IAM Conditions were not preserved upon creating or updating rolesets. This could potentially allow a remote attacker to elevate their privileges. The estimated number of potentially affected devices worldwide is not specified.
Recommendations For versions prior to 1.13.0, update to Vault 1.13.0 to resolve the issue. As a temporary workaround, consider restricting access to the Google Cloud secrets engine until the update is applied. Avoid using the Google Cloud secrets engine for creating or updating rolesets until the issue is resolved.

Exploit

Correção

DoS

Incorrect Privilege Assignment

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-06028
BIT-VAULT-2023-5077
CVE-2023-5077
GHSA-86C6-3G63-5W64
GO-2023-2088

Produtos afetados

Hashicorp Vault
Red Os
Vault Enterprise