PT-2023-26093 · Hashicorp+1 · Vault Enterprise+1

Marc Billow

·

Published

2023-09-28

·

Updated

2024-09-26

·

CVE-2023-3775

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Vault Enterprise versions prior to 1.15.0 Vault Enterprise versions prior to 1.14.4 Vault Enterprise versions prior to 1.13.8
Description A Vault Enterprise Sentinel Role Governing Policy created by an operator to restrict access to resources in one namespace can be applied to requests outside in another non-descendant namespace, potentially resulting in denial of service.
Recommendations For Vault Enterprise versions prior to 1.15.0, update to version 1.15.0 or later. For Vault Enterprise versions prior to 1.14.4, update to version 1.14.4 or later. For Vault Enterprise versions prior to 1.13.8, update to version 1.13.8 or later.

Fix

DoS

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

ALT-PU-2024-3459
ALT-PU-2024-3678
ALT-PU-2024-4187
BIT-VAULT-2023-3775
CVE-2023-3775

Affected Products

Alt Linux
Vault Enterprise