PT-2023-9289 · Hashicorp+1 · Hashicorp Vault+2

CVE-2023-5077

·

Published

2023-09-28

·

Updated

2024-09-26

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions HashiCorp Vault versions prior to 1.13.0
Description The issue is related to the Google Cloud secrets engine in HashiCorp Vault and Vault Enterprise, where existing Google Cloud IAM Conditions were not preserved upon creating or updating rolesets. This could potentially allow a remote attacker to elevate their privileges. The estimated number of potentially affected devices worldwide is not specified.
Recommendations For versions prior to 1.13.0, update to Vault 1.13.0 to resolve the issue. As a temporary workaround, consider restricting access to the Google Cloud secrets engine until the update is applied. Avoid using the Google Cloud secrets engine for creating or updating rolesets until the issue is resolved.

Exploit

Fix

DoS

Incorrect Privilege Assignment

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06028
BIT-VAULT-2023-5077
CVE-2023-5077
GHSA-86C6-3G63-5W64
GO-2023-2088

Affected Products

Hashicorp Vault
Red Os
Vault Enterprise