Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pfmw-vj74-ph8g

Опубликовано: 02 дек. 2021
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

HashiCorp Vault Incorrect Permission Assignment for Critical Resource

HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multiple entity aliases exist for a specified entity and mount combination, potentially resulting in incorrect policy enforcement. Fixed in Vault and Vault Enterprise 1.7.6, 1.8.5, and 1.9.0.

Пакеты

Наименование

github.com/hashicorp/vault

go
Затронутые версииВерсия исправления

>= 0.11.0, < 1.7.6

1.7.6

Наименование

github.com/hashicorp/vault

go
Затронутые версииВерсия исправления

>= 1.8.0, < 1.8.5

1.8.5

EPSS

Процентиль: 51%
0.00281
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 6.5
redhat
около 4 лет назад

HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multiple entity aliases exist for a specified entity and mount combination, potentially resulting in incorrect policy enforcement. Fixed in Vault and Vault Enterprise 1.7.6, 1.8.5, and 1.9.0.

CVSS3: 6.5
nvd
около 4 лет назад

HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multiple entity aliases exist for a specified entity and mount combination, potentially resulting in incorrect policy enforcement. Fixed in Vault and Vault Enterprise 1.7.6, 1.8.5, and 1.9.0.

EPSS

Процентиль: 51%
0.00281
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-732