CVE-2023-3775Incorrect Privilege Assignment in Vault Enterprise

Severity
4.9MEDIUMNVD
EPSS
0.4%
top 39.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 29

Description

A Vault Enterprise Sentinel Role Governing Policy created by an operator to restrict access to resources in one namespace can be applied to requests outside in another non-descendant namespace, potentially resulting in denial of service. Fixed in Vault Enterprise 1.15.0, 1.14.4, 1.13.8.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 1.2 | Impact: 3.6

Affected Packages2 packages

CVEListV5hashicorp/vault_enterprise1.14.01.14.4+2
NVDhashicorp/vault0.11.01.13.8+1

🔴Vulnerability Details

1
GHSA
GHSA-37gg-8xjr-m6x4: A Vault Enterprise Sentinel Role Governing Policy created by an operator to restrict access to resources in one namespace can be applied to requests o2023-09-29

📋Vendor Advisories

1
Red Hat
hashicorp/vault: vault enterprise’s sentinel RGP policies allowed for cross-namespace denial of service2023-09-29