CVE-2023-5077Incorrect Privilege Assignment in Vault Enterprise

Severity
7.5HIGHNVD
EPSS
0.2%
top 54.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 29
Latest updateAug 21

Description

The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating rolesets. Fixed in Vault 1.13.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

CVEListV5hashicorp/vault_enterprise0.10.01.13.0
NVDhashicorp/vault0.10.01.13.0

🔴Vulnerability Details

3
OSV
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault2024-08-21
OSV
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability2023-09-29
GHSA
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability2023-09-29

📋Vendor Advisories

1
Red Hat
hashicorp/vault: Google Cloud Secrets Engine Removed Existing IAM Conditions When Creating / Updating Rolesets2023-09-29