CVE-2021-42135Improper Privilege Management in Hashicorp Vault

Severity
8.1HIGHNVD
EPSS
0.2%
top 59.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 11
Latest updateAug 21

Description

HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than intended, e.g., a user with read permission for the /gcp/roleset/* path may be able to issue Google Cloud service account credentials.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages2 packages

Gogithub.com/hashicorp_vault1.8.01.8.5+1
NVDhashicorp/vault1.8.01.8.4

🔴Vulnerability Details

3
OSV
Incorrect Privilege Assignment in HashiCorp Vault in github.com/hashicorp/vault2024-08-21
OSV
Incorrect Privilege Assignment in HashiCorp Vault2021-10-12
GHSA
Incorrect Privilege Assignment in HashiCorp Vault2021-10-12

📋Vendor Advisories

1
Red Hat
vault: Google Cloud credential disclosure2021-10-11