PT-2021-23415 · Hashicorp · Vault Enterprise+1
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
HashiCorp Vault and Vault Enterprise versions 1.7.0 through 1.7.4
HashiCorp Vault and Vault Enterprise versions 1.8.0 through 1.8.3
Description
The issue allows a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities.
Recommendations
For HashiCorp Vault and Vault Enterprise versions 1.7.0 through 1.7.4, update to version 1.7.5 to resolve the issue.
For HashiCorp Vault and Vault Enterprise versions 1.8.0 through 1.8.3, update to version 1.8.4 to resolve the issue.
Fix
Incorrect Permission
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hashicorp Vault
Vault Enterprise