PT-2023-9289 · Hashicorp+1 · Hashicorp Vault+2
Published
2023-09-28
·
Updated
2024-09-26
·
CVE-2023-5077
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
HashiCorp Vault versions prior to 1.13.0
Description
The issue is related to the Google Cloud secrets engine in HashiCorp Vault and Vault Enterprise, where existing Google Cloud IAM Conditions were not preserved upon creating or updating rolesets. This could potentially allow a remote attacker to elevate their privileges. The estimated number of potentially affected devices worldwide is not specified.
Recommendations
For versions prior to 1.13.0, update to Vault 1.13.0 to resolve the issue. As a temporary workaround, consider restricting access to the Google Cloud secrets engine until the update is applied. Avoid using the Google Cloud secrets engine for creating or updating rolesets until the issue is resolved.
Fix
Incorrect Permission
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hashicorp Vault
Red Os
Vault Enterprise