Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9g4h-h484-3578

Опубликовано: 23 окт. 2025
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass

Vault and Vault Enterprise's ("Vault") AWS Auth method may be susceptible to authentication bypass if the role of the configured bound_principal_iam is the same across AWS accounts, or uses a wildcard. This vulnerability is fixed in Vault Community Edition 1.21.0 and Vault Enterprise 1.21.0, 1.20.5, 1.19.11, and 1.16.27.

Пакеты

Наименование

github.com/hashicorp/vault

go
Затронутые версииВерсия исправления

>= 0.6.0, < 1.21.0

1.21.0

EPSS

Процентиль: 40%
0.00487
Низкий

8.1 High

CVSS3

Дефекты

CWE-288

Связанные уязвимости

CVSS3: 8.1
redhat
10 месяцев назад

Vault and Vault Enterprise’s (“Vault”) AWS Auth method may be susceptible to authentication bypass if the role of the configured bound_principal_iam is the same across AWS accounts, or uses a wildcard. This vulnerability, CVE-2025-11621, is fixed in Vault Community Edition 1.21.0 and Vault Enterprise 1.21.0, 1.20.5, 1.19.11, and 1.16.27

CVSS3: 8.1
nvd
10 месяцев назад

Vault and Vault Enterprise’s (“Vault”) AWS Auth method may be susceptible to authentication bypass if the role of the configured bound_principal_iam is the same across AWS accounts, or uses a wildcard. This vulnerability, CVE-2025-11621, is fixed in Vault Community Edition 1.21.0 and Vault Enterprise 1.21.0, 1.20.5, 1.19.11, and 1.16.27

CVSS3: 8.1
fstec
10 месяцев назад

Уязвимость компонента bound_principal_iam системы контроля доступом Vault и платформы для архивирования корпоративной информации Vault Enterprise, позволяющая нарушителю обойти существующие ограничения безопасности

CVSS3: 8.1
redos
3 месяца назад

Уязвимость vault

CVSS3: 8.1
redos
9 месяцев назад

Уязвимость vault

EPSS

Процентиль: 40%
0.00487
Низкий

8.1 High

CVSS3

Дефекты

CWE-288