Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-38553

Опубликовано: 13 авг. 2021
Источник: redhat
CVSS3: 4.4

Описание

HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0.

A flaw was found in the Vault package. Affected versions of the HashiCorp Vault initialized an underlying database file associated with the Integrated Storage feature, which has excessively broad filesystem permissions.

Отчет

Only Vault clusters utilizing Integrated Storage are affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-loki-rhel8Not affected
OpenShift Service Mesh 2.0servicemeshNot affected
Red Hat Advanced Cluster Management for Kubernetes 2vaultNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-installerFix deferred
Red Hat OpenShift Container Platform 4openshift4/topology-aware-lifecycle-manager-rhel8-operatorFix deferred
Red Hat Openshift Container Storage 4ocs4/cephcsi-rhel8Out of support scope
Red Hat Openshift Container Storage 4ocs4/mcg-rhel8-operatorOut of support scope
Red Hat Openshift Container Storage 4ocs4/ocs-rhel8-operatorOut of support scope
Red Hat Openshift Container Storage 4ocs4/rook-ceph-rhel8-operatorOut of support scope
Red Hat Openshift Data Foundation 4odf4/cephcsi-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-276
https://bugzilla.redhat.com/show_bug.cgi?id=1995209vault: Underlying database file with excessively broad filesystem permissions

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
nvd
больше 4 лет назад

HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0.

CVSS3: 9.8
github
больше 4 лет назад

HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0

4.4 Medium

CVSS3