PT-2023-9289 · Hashicorp+1 · Hashicorp Vault+2

Published

2023-09-28

·

Updated

2024-09-26

·

CVE-2023-5077

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions HashiCorp Vault versions prior to 1.13.0
Description The issue is related to the Google Cloud secrets engine in HashiCorp Vault and Vault Enterprise, where existing Google Cloud IAM Conditions were not preserved upon creating or updating rolesets. This could potentially allow a remote attacker to elevate their privileges. The estimated number of potentially affected devices worldwide is not specified.
Recommendations For versions prior to 1.13.0, update to Vault 1.13.0 to resolve the issue. As a temporary workaround, consider restricting access to the Google Cloud secrets engine until the update is applied. Avoid using the Google Cloud secrets engine for creating or updating rolesets until the issue is resolved.

Fix

Incorrect Permission

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

BDU:2024-06028
BIT-VAULT-2023-5077
CVE-2023-5077
GHSA-86C6-3G63-5W64
GO-2023-2088

Affected Products

Hashicorp Vault
Red Os
Vault Enterprise