Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qv95-g3gm-x542

Опубликовано: 12 окт. 2021
Источник: github
Github: Прошло ревью
CVSS3: 2.9

Описание

Hashicorp Vault Privilege Escalation Vulnerability

HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault Enterprise 1.7.5 and 1.8.4.

Пакеты

Наименование

github.com/hashicorp/vault

go
Затронутые версииВерсия исправления

< 1.7.5

1.7.5

Наименование

github.com/hashicorp/vault

go
Затронутые версииВерсия исправления

>= 1.8.0, < 1.8.4

1.8.4

EPSS

Процентиль: 48%
0.00254
Низкий

2.9 Low

CVSS3

Дефекты

CWE-269
CWE-732

Связанные уязвимости

CVSS3: 5.4
redhat
больше 4 лет назад

HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault Enterprise 1.7.5 and 1.8.4.

CVSS3: 2.9
nvd
больше 4 лет назад

HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault Enterprise 1.7.5 and 1.8.4.

EPSS

Процентиль: 48%
0.00254
Низкий

2.9 Low

CVSS3

Дефекты

CWE-269
CWE-732