Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-38553

Опубликовано: 13 авг. 2021
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0.

A flaw was found in the Vault package. Affected versions of the HashiCorp Vault initialized an underlying database file associated with the Integrated Storage feature, which has excessively broad filesystem permissions.

Отчет

Only Vault clusters utilizing Integrated Storage are affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-loki-rhel8Not affected
OpenShift Service Mesh 2.0servicemeshNot affected
Red Hat Advanced Cluster Management for Kubernetes 2vaultNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-installerFix deferred
Red Hat OpenShift Container Platform 4openshift4/topology-aware-lifecycle-manager-rhel8-operatorFix deferred
Red Hat Openshift Container Storage 4ocs4/cephcsi-rhel8Out of support scope
Red Hat Openshift Container Storage 4ocs4/mcg-rhel8-operatorOut of support scope
Red Hat Openshift Container Storage 4ocs4/ocs-rhel8-operatorOut of support scope
Red Hat Openshift Container Storage 4ocs4/rook-ceph-rhel8-operatorOut of support scope
Red Hat Openshift Data Foundation 4odf4/cephcsi-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-276
https://bugzilla.redhat.com/show_bug.cgi?id=1995209vault: Underlying database file with excessively broad filesystem permissions

EPSS

Процентиль: 26%
0.00086
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
nvd
почти 4 года назад

HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0.

CVSS3: 9.8
github
почти 4 года назад

HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0

EPSS

Процентиль: 26%
0.00086
Низкий

4.4 Medium

CVSS3