Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m979-w9wj-qfj9

Опубликовано: 30 янв. 2024
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

HashiCorp Vault Improper Privilege Management

HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Group membership inadvertently include Groups the Entity no longer has permissions to. Fixed in 1.3.4.

Пакеты

Наименование

github.com/hashicorp/vault

go
Затронутые версииВерсия исправления

>= 0.9.0, < 1.3.4

1.3.4

EPSS

Процентиль: 45%
0.00229
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 5.3
redhat
почти 6 лет назад

HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Group membership inadvertently include Groups the Entity no longer has permissions to. Fixed in 1.3.4.

CVSS3: 5.3
nvd
почти 6 лет назад

HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Group membership inadvertently include Groups the Entity no longer has permissions to. Fixed in 1.3.4.

EPSS

Процентиль: 45%
0.00229
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-269