PT-2023-9289 · Hashicorp+1 · Hashicorp Vault+2
CVE-2023-5077
·
Publicado
2023-09-28
·
Atualizado
2024-09-26
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
HashiCorp Vault versions prior to 1.13.0
Description
The issue is related to the Google Cloud secrets engine in HashiCorp Vault and Vault Enterprise, where existing Google Cloud IAM Conditions were not preserved upon creating or updating rolesets. This could potentially allow a remote attacker to elevate their privileges. The estimated number of potentially affected devices worldwide is not specified.
Recommendations
For versions prior to 1.13.0, update to Vault 1.13.0 to resolve the issue. As a temporary workaround, consider restricting access to the Google Cloud secrets engine until the update is applied. Avoid using the Google Cloud secrets engine for creating or updating rolesets until the issue is resolved.
Exploit
Correção
DoS
Incorrect Privilege Assignment
Incorrect Permission
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Hashicorp Vault
Red Os
Vault Enterprise