Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f9ch-h8j7-8jwg

Опубликовано: 02 мая 2025
Источник: github
Github: Прошло ревью
CVSS3: 6.6

Описание

Hashicorp Vault Community vulnerable to Incorrect Authorization

Vault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued token, resulting in the potential bypass of the bound_locations parameter on login. Fixed in Vault Community Edition 1.19.1 and Vault Enterprise 1.19.1, 1.18.7, 1.17.14, 1.16.18.

Пакеты

Наименование

github.com/hashicorp/vault

go
Затронутые версииВерсия исправления

>= 1.10.0, < 1.19.1

1.19.1

EPSS

Процентиль: 17%
0.00056
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.6
redhat
4 месяца назад

Vault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued token, resulting in the potential bypass of the bound_locations parameter on login. Fixed in Vault Community Edition 1.19.1 and Vault Enterprise 1.19.1, 1.18.7, 1.17.14, 1.16.18.

CVSS3: 6.6
nvd
4 месяца назад

Vault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued token, resulting in the potential bypass of the bound_locations parameter on login. Fixed in Vault Community Edition 1.19.1 and Vault Enterprise 1.19.1, 1.18.7, 1.17.14, 1.16.18.

CVSS3: 6.6
redos
около 2 месяцев назад

Уязвимость vault

EPSS

Процентиль: 17%
0.00056
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-863