CVE-2021-43998Incorrect Permission Assignment in Hashicorp Vault

Severity
6.5MEDIUMNVD
EPSS
0.3%
top 48.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 30
Latest updateAug 21

Description

HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multiple entity aliases exist for a specified entity and mount combination, potentially resulting in incorrect policy enforcement. Fixed in Vault and Vault Enterprise 1.7.6, 1.8.5, and 1.9.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:NExploitability: 1.2 | Impact: 5.2

Affected Packages2 packages

Gogithub.com/hashicorp_vault0.11.01.7.6+1
NVDhashicorp/vault0.11.01.7.5+1

🔴Vulnerability Details

3
OSV
HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault2024-08-21
GHSA
HashiCorp Vault Incorrect Permission Assignment for Critical Resource2021-12-02
OSV
HashiCorp Vault Incorrect Permission Assignment for Critical Resource2021-12-02

📋Vendor Advisories

1
Red Hat
vault: incorrect policy enforcement2021-11-18